Frequently Asked Questions

Quick answers about how Secret Keybox handles your data, licensing, and setup. Can't find what you need? Email contact@secretkeybox.com.

What happens to my data?

Your credentials live entirely inside your own Salesforce org, encrypted at rest. We have no way to access, read, or export them — and because the encryption key never leaves your org, we have no way to recover them either. Your secrets are yours alone. Just keep your org and its backups safe: there's no master key on our side to fall back on.

Can anyone at Secret Keybox see my passwords?

No. Your secrets are encrypted inside your own Salesforce org with a key that never leaves it, so no one on our side can read, export, or recover them. We built it that way on purpose — the fewer people who can see your passwords, the better. Ideally, just you.

How are my passwords encrypted?

Every secret is encrypted with AES-256 before it's stored, using a key unique to your org and derived per owner. Nothing is kept in plain text — the readable value only appears when you explicitly reveal or copy it in the app.

What does a license include?

One license covers one Salesforce org. Install it there and grant access to as many users as you like — it's licensed per org, not per user. Your whole team is welcome, and there's no per-seat math to do.

Which Salesforce editions are supported?

Secret Keybox needs an edition that supports Apex and custom objects — that's Enterprise, Unlimited, Performance, and Developer editions, with Lightning Experience enabled and admin rights to install. Lighter editions like Starter, Group, and Professional require the app to be distributed through the AppExchange: Secret Keybox has already passed the AppExchange Security Review, so support for those editions becomes possible once our listing goes live.

Why isn't Secret Keybox on the AppExchange yet?

Secret Keybox has passed the Salesforce AppExchange Security Review — the in-depth security audit every AppExchange app must clear. The public listing is now in preparation. Until it goes live, the package is distributed via a direct install link (same package, same product), and we're happy to walk any admin or security team through the architecture on a call.

How do I install Secret Keybox?

After your purchase we email you an installation link and instructions, usually within 24 hours on business days. A Salesforce admin installs the package and assigns the permission set — no command line, no drama.

How do I grant access to other users?

Assign them the Secret Keybox permission set and they're in. That's the whole ceremony — no extra configuration required.

Can I share a credential with my team?

Yes. You can share a credential with individual users or with whole groups, and you can set an expiration date when access should only be temporary — perfect for the contractor who needs the staging login until Friday.

What happens when a share expires or someone leaves a group?

Access is revoked automatically — no cleanup required from you. When a share reaches its expiration date, or a member leaves a group, their access to that credential goes away on its own.

Can I use it on my Sandbox?

Absolutely. Secret Keybox runs happily on both Production and Sandbox orgs — it's your call. Just remember that each org has its own encryption key, so credentials encrypted in Production can't be decrypted in a Sandbox (and vice versa). Different vault, different key.

What happens if I cancel or my subscription ends?

You keep full access until the end of the term you've already paid for — cancelling simply stops future renewals. Once the term ends, the license ends too, and the app should be uninstalled. No surprise mid-term cut-offs.