For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security & Compliance

How sfp server's single-tenant architecture, approval gates, and append-only audit trails support change control and compliance programs such as SOX and SOC 2.

sfp server includes change-control and audit features: approval gates on release execution and other sensitive operations, append-only audit trails, and a compliance export over the approval record. This section documents what is recorded, how the controls work, and how to retrieve the evidence.

Single-tenant by design

Every sfp server instance serves exactly one organization. The control plane (API), the execution plane (workers), the database, and the queueing infrastructure run as one isolated stack — there is no shared compute or shared data plane with any other customer.

  • Self-hosted deployments run entirely on infrastructure you provision and operate. Your data never leaves your network boundary unless you configure an integration that sends it somewhere.

  • Cloud-hosted deployments run as a dedicated instance per tenant. Isolation is at the instance level, not at the row level of a shared database.

Three properties follow from this:

  1. Trust boundary. Everyone with access to an instance is a member of the organization it serves. Authorization inside the instance is role-based (member, owner, application tokens) — see Authentication & Security Architecture.

  2. Fixed network egress. All traffic to registered Salesforce orgs — DevHub, production, sandboxes — originates from the instance's egress IP addresses. Org access can therefore be restricted to those addresses on the Salesforce side. See Restricting Salesforce Org Access by IP.

  3. Audit data residency. Audit records are stored in the instance's own database; retention and archival are controlled by the operator.

Contents

Page
Covers

Release Approvals

Per-environment approval gates on release execution, segregation of duties, approval channels (web UI, GitHub, Slack, Azure DevOps), and the approval lifecycle

Audit Trails

Append-only audit logs for credentials, secrets, environment access, and approvals; how to query them; the SOX compliance export

Locking DevHub and production access to your server's egress IP using Salesforce profile login IP ranges

Last updated

Was this helpful?