Horus Eye · Trust Layer

Metadata-first AI. We show you what it saw.

Horus Eye puts AI on top of your Salesforce org’s metadata — never its records. Before any request reaches a model, the context is built from an allowlist, classified by tier, sanitized by pattern and walled to one tenant; on the way back, an output firewall checks every answer. Every call gets an audit id and an AI Data Scope manifest you can open. That is Salesforce AI security you can inspect: we don’t ask you to trust the AI — we show you what it was allowed to see.

Try Horus Eye See a live Trust page

The Horus Eye Protected AI badge with its five guarantees: Minimum Necessary Context, Metadata-First, Tenant Isolated, No-Training AI, Auditable
The badge every deployment carries — on sign-in, on every Protected Deep Read, and on its own public trust page.

Nine steps, one gateway

The path

Every AI request in Horus Eye travels the same nine steps — from your org’s metadata through minimizer, classifier and sanitizer, into the one gateway that talks to the model, and back through the output firewall to the audit ledger and to you. Exactly one place in the product calls a model; a guard test fails the build if a second caller ever appears.

Data flow: Salesforce metadata → minimizer → classifier → sanitizer → AI gateway → model → output firewall → ledger and you1. Salesforce orgmetadata read-only · records never captured2. Scanner → Horus Eye DBorg-scoped rows · no bodies stored3. Minimizerallowlist by key · minimum necessary4. Classifiertiers 0–2 only · tier 4 never5. Sanitizer15 patterns · optional pseudonyms6. AI Gatewaytenant wall · untrusted-evidence boundary7. Modelno training · retention as declared8. Output firewallsecrets · PII · foreign ids · verdicts9. Ledger + youaudit id · AI Data Scope · basis labels
Nine steps, one gateway. Steps 3–6 and 8 are deterministic code, not the model’s judgement.

The five guarantees on the badge

Protected AI

Minimum necessary context

Every AI request is built from an allowlist, not from your org. Anything not on the allowlist does not exist to the model.

Metadata-first

Customer record data is never captured by the scanner, so it is never sent. Account, Contact, Opportunity and Case records — and files — never travel.

Tenant isolated

A request can only ever contain one org, and the gateway refuses anything else.

No-training AI

Your Salesforce data isn’t the model’s training data. The model provider is Anthropic (Claude); API inputs and outputs are not used for training.

Auditable

Every AI request has an audit id and a data-scope manifest you can open — and quote back to us.

One gateway behind them

Every AI call in Horus Eye goes through a single gateway — audited, sanitized, logged. The guarantees are enforced in one place, not promised in many.

Classified and sanitized before anything leaves

Before the model

Every field in a context is classified before it can travel — five data tiers, from product knowledge to sensitive. The sensitive tier is never allowed, PII and files are never allowed, and an unclassified key refuses the request before the model is called.

A deterministic, 15-pattern sanitizer then runs twice — on the context, and again inside the gateway on every outbound message: emails, phone numbers, IPs, record ids, keys, tokens and credentials are removed by pattern before every call — never left to the model’s judgement.

Optional name masking goes further: your custom object, field, Flow and Apex names can travel as tokens the provider never sees resolved — and come back restored in the answer.

And your metadata is evidence, never instructions — a description that says “ignore previous instructions” is reported, not obeyed.

See what the AI saw — before and after

AI Data Scope

Before a Deep Read runs, the AI Data Scope shows exactly what will be sent — categories, counts, tiers, route and policy — computed from the same object the request is built from. After, the same panel shows what was sent, what the output firewall checked, and the audit id.

AI Data Scope before a Deep Read: exactly what will be sent, with record data and files marked never captured
Before: what will be sent — and the audit id “assigned when the read runs”.
AI Data Scope after a Deep Read: what was sent, the output firewall report, pseudonym count and the audit id
After: what was sent, what the firewall checked, and the audit id you can quote back to us.

Honest output — evidence, not verdicts

On the way back

Every claim a Deep Read makes is hedged and cites the fact it rests on — a fabricated citation fails the read. Basis chips separate what the AI observed from what it calculated, inferred or recommends, so you can always tell observation from inference.

And every answer is checked on the way out by a six-check output firewall: a leaked secret, or a component that was never in your org, is rejected — not shown.

A Protected Deep Read with the badge, basis chips for observed, calculated, inferred and recommended statements, and evidence chips under each claim
Every statement says what it rests on; every claim cites the fact behind it.

You’re in control — per org, on the record

Trust Center

AI is off by default — and Deep Read has its own switch. You decide what the AI may see, per org, from a Trust Center where every change is logged with who made it.

Three privacy modes: metadata-only by default; live counts — numbers, never rows — only when you say so; and a private endpoint, available for enterprise deployments, when you need one.

Cross-org learning is opt-in, off by default: your org never teaches another customer’s Horus Eye unless you say so — and even then, the pattern travels, not your names.

The Horus Eye Trust Center: AI and Deep Read switches, name masking, privacy mode, contribution, allowed data classes and the change log
Off by default. You decide what AI may see, per org, with a written record of every change.

Straight answers for your security team

Seven questions

The Salesforce AI security questions a review will ask — answered the way the product answers them, on every deployment’s own public trust page.

What leaves Salesforce?

Metadata only — component types, API names, dependencies, configuration — classified by tier and sanitized by a 15-pattern sanitizer before every call. Customer record data and files are never captured by the scanner, so they are never sent. (One documented exception: Apex trigger consolidation sends component source — sanitized, classified, on the ledger, and the AI Data Scope says so.)

Where does it go?

Through one gateway to the model provider, Anthropic (Claude). The route — provider, model, region and retention class — is read from configuration and printed on every request’s manifest.

Who retains what?

Horus Eye stores metadata and the audit manifests — never records, never prompts. Model-side retention is the provider’s declared class, shown on the manifest for your deployment.

Does it train the model?

No. Your Salesforce data isn’t the model’s training data — Anthropic’s API does not use inputs or outputs for training.

How are tenants separated?

A request can only ever contain one org, and the gateway refuses anything else before the model is called.

What is logged?

One row per model call: an audit id (DR-YYYYMMDD-NNNNN), the categories, counts and tiers that were sent, the route and policy, the output-firewall report and token counts. Never the prompt, never a record.

How do I turn it off?

It ships off. AI — and Deep Read separately — are per-org switches in the Trust Center, off by default, and every change is logged with who made it and when.

The Admin Trust view: the configured model route, every org’s switches, seven-day gateway counts and the cross-org settings audit
For operators: the route as configured, every org’s switches, seven-day gateway counts, and the settings audit across orgs.

Every Horus Eye deployment also publishes its own live trust page, derived from its running configuration — see one here. The full Trust Layer runs to 23 documented measures; ask us for the architecture.

See the Trust Layer for yourself

The trust story is in the product, not the brochure: open the AI Data Scope on your own org’s first read.

Try Horus Eye Talk to an Architect All Horus Eye pages