Horus Eye · Trust Layer
Metadata-first AI. We show you what it saw.
Horus Eye puts AI on top of your Salesforce org’s metadata — never its records. Before any request reaches a model, the context is built from an allowlist, classified by tier, sanitized by pattern and walled to one tenant; on the way back, an output firewall checks every answer. Every call gets an audit id and an AI Data Scope manifest you can open. That is Salesforce AI security you can inspect: we don’t ask you to trust the AI — we show you what it was allowed to see.

Nine steps, one gateway
The pathEvery AI request in Horus Eye travels the same nine steps — from your org’s metadata through minimizer, classifier and sanitizer, into the one gateway that talks to the model, and back through the output firewall to the audit ledger and to you. Exactly one place in the product calls a model; a guard test fails the build if a second caller ever appears.
The five guarantees on the badge
Protected AIMinimum necessary context
Every AI request is built from an allowlist, not from your org. Anything not on the allowlist does not exist to the model.
Metadata-first
Customer record data is never captured by the scanner, so it is never sent. Account, Contact, Opportunity and Case records — and files — never travel.
Tenant isolated
A request can only ever contain one org, and the gateway refuses anything else.
No-training AI
Your Salesforce data isn’t the model’s training data. The model provider is Anthropic (Claude); API inputs and outputs are not used for training.
Auditable
Every AI request has an audit id and a data-scope manifest you can open — and quote back to us.
One gateway behind them
Every AI call in Horus Eye goes through a single gateway — audited, sanitized, logged. The guarantees are enforced in one place, not promised in many.
Classified and sanitized before anything leaves
Before the modelEvery field in a context is classified before it can travel — five data tiers, from product knowledge to sensitive. The sensitive tier is never allowed, PII and files are never allowed, and an unclassified key refuses the request before the model is called.
A deterministic, 15-pattern sanitizer then runs twice — on the context, and again inside the gateway on every outbound message: emails, phone numbers, IPs, record ids, keys, tokens and credentials are removed by pattern before every call — never left to the model’s judgement.
Optional name masking goes further: your custom object, field, Flow and Apex names can travel as tokens the provider never sees resolved — and come back restored in the answer.
And your metadata is evidence, never instructions — a description that says “ignore previous instructions” is reported, not obeyed.
See what the AI saw — before and after
AI Data ScopeBefore a Deep Read runs, the AI Data Scope shows exactly what will be sent — categories, counts, tiers, route and policy — computed from the same object the request is built from. After, the same panel shows what was sent, what the output firewall checked, and the audit id.


Honest output — evidence, not verdicts
On the way backEvery claim a Deep Read makes is hedged and cites the fact it rests on — a fabricated citation fails the read. Basis chips separate what the AI observed from what it calculated, inferred or recommends, so you can always tell observation from inference.
And every answer is checked on the way out by a six-check output firewall: a leaked secret, or a component that was never in your org, is rejected — not shown.

You’re in control — per org, on the record
Trust CenterAI is off by default — and Deep Read has its own switch. You decide what the AI may see, per org, from a Trust Center where every change is logged with who made it.
Three privacy modes: metadata-only by default; live counts — numbers, never rows — only when you say so; and a private endpoint, available for enterprise deployments, when you need one.
Cross-org learning is opt-in, off by default: your org never teaches another customer’s Horus Eye unless you say so — and even then, the pattern travels, not your names.

Straight answers for your security team
Seven questionsThe Salesforce AI security questions a review will ask — answered the way the product answers them, on every deployment’s own public trust page.
What leaves Salesforce?
Metadata only — component types, API names, dependencies, configuration — classified by tier and sanitized by a 15-pattern sanitizer before every call. Customer record data and files are never captured by the scanner, so they are never sent. (One documented exception: Apex trigger consolidation sends component source — sanitized, classified, on the ledger, and the AI Data Scope says so.)
Where does it go?
Through one gateway to the model provider, Anthropic (Claude). The route — provider, model, region and retention class — is read from configuration and printed on every request’s manifest.
Who retains what?
Horus Eye stores metadata and the audit manifests — never records, never prompts. Model-side retention is the provider’s declared class, shown on the manifest for your deployment.
Does it train the model?
No. Your Salesforce data isn’t the model’s training data — Anthropic’s API does not use inputs or outputs for training.
How are tenants separated?
A request can only ever contain one org, and the gateway refuses anything else before the model is called.
What is logged?
One row per model call: an audit id
(DR-YYYYMMDD-NNNNN), the categories, counts and tiers that were sent, the route and
policy, the output-firewall report and token counts. Never the prompt, never a record.
How do I turn it off?
It ships off. AI — and Deep Read separately — are per-org switches in the Trust Center, off by default, and every change is logged with who made it and when.

Every Horus Eye deployment also publishes its own live trust page, derived from its running configuration — see one here. The full Trust Layer runs to 23 documented measures; ask us for the architecture.
See the Trust Layer for yourself
The trust story is in the product, not the brochure: open the AI Data Scope on your own org’s first read.
Try Horus Eye Talk to an Architect All Horus Eye pages