DashyCast.
Security & trust

Your Salesforce access stays under your control.

DashyCast is designed to fetch only the data needed to render your published charts, while keeping credentials, organizations, and private assets protected.

Credentials are protected

DashyCast never stores your Salesforce password. Customer-provided Salesforce app secrets are encrypted with AES-256-GCM, and production traffic is protected with HTTPS.

Access stays scoped

DashyCast can only read what the Salesforce integration user is permitted to access. You control that user and its Salesforce permissions.

Organizations are isolated

Database row-level security and server-side membership checks keep each organization’s connections, assets, and settings separate.

Sessions are hardened

Authentication uses secure, HTTP-only cookies in production. Role checks protect organization administration, publishing, billing, and member management.

Sharing is explicit

Public assets are accessible to anyone with their URL by design. Private assets require a signed-in member of the owning organization.

Disconnect means disconnect

Disconnecting Salesforce removes the connection and its published assets together in one database transaction, preventing partial cleanup.

What DashyCast stores

DashyCast stores account, organization, connection, publishing, and subscription settings needed to operate the service. Published Salesforce report and dashboard responses are stored as cached copies so DashyCast can render and refresh each asset; Salesforce data is not used for advertising or sold.

Stripe processes payment details, Supabase provides authentication and database infrastructure, and Vercel hosts the service. More detail is available in the Privacy Policy.

Questions about your setup?

We are happy to explain exactly how DashyCast connects to your Salesforce organization.

Contact us