Platform

Security is Salesforce's. So is your data.Kugamon runs inside your org and never holds a copy.

Kugamon is built and delivered entirely on Salesforce as a managed package. That is the whole security story: your quotes, orders, invoices, payments and subscriptions are records in your own org, governed by your org's permissions and protected by Salesforce's infrastructure. This page describes the controls Kugamon operates as a company, and is careful about which certifications are Salesforce's rather than ours.

2009
in production since
1+ / month
releases, tested in sandboxes before production
150+
companies worldwide

Kugamon is a managed package that has passed the Salesforce AppExchange security review and runs entirely inside your Salesforce org. Customer data is handled by Salesforce — encrypted in transit and at rest, in data centers certified to ISO 27001, SOC 2, FedRAMP, HIPAA and NIST, among others — and Kugamon does not have access to it. Field-level security applies to every transaction record. The certifications below are Salesforce's; the controls are ours.

Control environment

  • A dedicated security compliance function implements and monitors Kugamon's security framework and controls.
  • The framework consists of policies, procedures and controls that align to ISO 27001, SOC 2, FedRAMP and GDPR and other privacy requirements.
  • Kugamon is built on Salesforce, so it uses Salesforce's cloud data centers, which maintain network architecture and data-layer controls that meet the requirements of the most security-sensitive organizations.
  • Employees attend security awareness training on hire and annually, and are required to adhere to the Kugamon code of conduct.
  • Annual risk assessments address current and emerging risks.
  • Change management procedures cover all changes to the organization and to Kugamon's offerings.

Physical security

Kugamon is built and delivered entirely on Salesforce. Salesforce data centers maintain controls at the perimeter, infrastructure and environmental layers, audited regularly against a range of security certifications and standards. Kugamon reviews those certifications annually to confirm the standards are maintained.

The data centers hold several security-related certifications, including ISO 27001, SOC 2, FedRAMP, HIPAA and NIST, and others. These are Salesforce's certifications, published on the Salesforce Trust and Compliance sites, where the latest vulnerability and penetration report summary for Salesforce Services is also available.

Application and network security

  • Kugamon follows industry-standard and Salesforce best practices in its application security framework.
  • All software releases and new features are reviewed and tested before release, under change management procedures.
  • Testing and staging environments are separate from production, and no actual customer data is ever used for testing.
  • Automated vulnerability scans run at regular intervals and findings are addressed under a vulnerability management process.
  • Automated monitoring, logging and system alerts are in place.
  • System access is role-based and least-privilege, including granting and revoking, and all admins and users are formally reviewed quarterly.

In practice, a release reaches customers the same way each month: pushed to sandboxes first, then to production, so an administrator can verify it against their own configuration. The release history page shows the cadence.

Salesforce security requirements

  • Kugamon is built entirely within Salesforce and is therefore subject to Salesforce's security policy requirements, which any application must demonstrate to be listed on the AppExchange.
  • Kugamon adheres to AppExchange security requirements, which require secure-coding best practices.
  • Kugamon is subject to Salesforce security reviews, which examine code quality and code security. Kugamon is a managed package, and passing that review is a condition of its AppExchange listing.

The governing documentation is Salesforce's ISVforce Guide and the AppExchange security requirements checklist, linked in the sources.

Security inside your org

Because every Kugamon record is a Salesforce record, your org's security model is Kugamon's security model:

  • Object and field-level security — profiles, permission sets and field-level security apply to Quotes, Orders, Invoices, Payments, Contracts and Subscriptions as they do to any object, and Kugamon enforces field-level security on every transaction record.
  • Sharing and visibility — record ownership, role hierarchy and sharing rules govern who sees which transactions.
  • Restricted records — a Quote, Order or Invoice can be marked Restricted, which disables emailing and online preview and watermarks the PDF, so records not approved for external viewing cannot leave the org by accident.
  • Customer-facing pages — the online Quote, Order, Invoice and Payment pages run through a Salesforce Site guest user to which the administrator assigns the Kugamon Site Guest User permission set, so what a customer can reach is governed by that permission set and Salesforce's guest-user rules.
  • Payments — card and ACH transactions are processed by the connected gateway (Stripe, Authorize.Net, PayPal or eWay); the Payment record stores the processor's transaction ID, card type and last four digits. Saving a payment method for reuse is off by default and enabled by Kugamon Support on request.

Encryption

  • Customer data is handled by Salesforce, which means it is encrypted in transit and at rest.
  • Kugamon does not have access to customer data.

Salesforce publishes its first-party storage encryption summary on its compliance site.

Availability

  • Service delivery is handled by Salesforce, which performs regular backups of data; backup testing is performed annually.
  • Kugamon's incident response and disaster recovery policies and procedures, and their testing and team training, are performed annually.

Questions about any of the above go to support@kugamon.com. The contractual terms are in the Master Subscription Agreement and the privacy policy.

Common questions

Security is Salesforce's. So is your data. — questions

All questions →

In your Salesforce org. Kugamon is a managed package installed into your org; every quote, order, invoice, payment, contract and subscription is a Salesforce record there. Kugamon runs no external database or service that holds customer data, and Kugamon does not have access to customer data.

The certifications belong to Salesforce's data centers — ISO 27001, SOC 2, FedRAMP, HIPAA, NIST and others — because that is where the data is stored and processed. Kugamon's own security framework aligns its policies, procedures and controls to ISO 27001, SOC 2, FedRAMP and GDPR requirements, and Kugamon reviews Salesforce's certifications annually. Kugamon does not claim those certifications for itself.

Yes. Every managed package listed on the AppExchange must pass Salesforce's security review, which examines code quality and code security against Salesforce's secure-coding requirements, and Kugamon is subject to it on an ongoing basis. Kugamon has been in production since 2009 and is listed on the AppExchange.

Yes, all of them. Object permissions, field-level security, sharing rules, profiles and permission sets apply to Kugamon's objects exactly as they do to Accounts and Opportunities, and Kugamon enforces field-level security on every transaction record. A user who cannot see a field on an Invoice in Salesforce cannot see it in Kugamon, because Kugamon is Salesforce.

Customer data is handled by Salesforce, which encrypts it in transit and at rest; Salesforce publishes its first-party storage encryption summary on its compliance site. Because Kugamon holds no copy, there is no second encryption regime to audit.

Every release and new feature is reviewed and tested before release under Kugamon's change management procedures. Testing and staging environments are separate from production, no actual customer data is used for testing, and releases are pushed to customer sandboxes before production so administrators can verify them first.

4.9★★★★★134 public reviews

What Salesforce admins say on AppExchange

Quoted verbatim from the Kugamon listing on AppExchange. Reviewer names and dates as published there. Read all 134, including the critical ones →

★★★★★

Easy to understand, easy to implement

“This SFDC-native platform is lightweight but powerful, bringing the entire sales process onto one pane of glass. No more disconnected Opportunities and Quotes/Orders, no more fractured approval processes, just more control over everything. Implementation is a breeze.”

★★★★★

Clear & Intuitive

“The Kugamon team is incredibly responsive and handle support questions very quickly. It’s clear they genuinely value customer feedback and are always innovating.”

★★★★★

A new bar for RevOps

“As someone who has set up Salesforce CPQ before, I found Kugamon to be much more straightforward and easier to use. It took us just a few weeks to get going, rather than the few months or even years required by other systems.”

Next step

Configure, price, quote, sign, bill, collect, and renew.

All natively in Salesforce. Deploys in weeks, not months, usually without a systems integrator.