Last reviewed: September 2, 2026
Audience: Prospective customers, procurement teams, security reviewers, IT administrators, and GoldFinch RFQ/RFP response teams
This article provides reusable answers to common technical, architecture, security, availability, support, and compliance questions about GoldFinch ERP/WMS.
GoldFinch is a native Salesforce application. Core GoldFinch application logic, configuration, and customer data operate within the customer’s Salesforce organization. GoldFinch does not require a separate GoldFinch-hosted runtime environment, application server, or database.
Contract terms, the customer’s Salesforce edition, optional Salesforce products, integrations, and customer security configuration can change the final answer. Confirm those items for each proposal. The applicable contract and statement of work control if they differ from this article.
Architecture and hosting
Is GoldFinch a SaaS solution?
Yes. GoldFinch ERP/WMS is delivered as a SaaS application built natively on the Salesforce Platform. Core application logic and business data run within the customer’s Salesforce organization. The customer does not need to host a separate GoldFinch application server or database.
What is the GoldFinch architecture?
| Layer | Components | Primary responsibility |
|---|---|---|
| Users and devices | Supported desktop browsers, Salesforce mobile app, and approved scanners and printers | Customer device standards, endpoint security, identity, and network access |
| Salesforce experience | Lightning applications, mobile-enabled pages, reports, and dashboards | GoldFinch and customer configuration, roles, usability, and form-factor testing |
| GoldFinch managed application | Lightning Web Components, Apex, Flow, approvals, and scheduled or batch processing | GoldFinch package and customer-specific configuration or extensions |
| Salesforce platform and data | Salesforce objects, files, security, audit capabilities, and APIs | Salesforce infrastructure and customer data governance and security configuration |
| Optional external systems | Financial, tax, payment, banking, EDI, shipping, ecommerce, identity, printing, analytics, and planning services | Scoped integration design, authentication, encryption, monitoring, and reconciliation |
Core GoldFinch processing occurs inside the Salesforce trust boundary. Browser and supported mobile traffic uses HTTPS/TLS. Approved external integrations use governed Salesforce interfaces and do not receive raw access to the underlying Salesforce database.
Does GoldFinch use an external hosting environment or database?
No. GoldFinch does not operate a separate production hosting environment or application database for core GoldFinch functions. Customer data remains in the customer’s Salesforce org. Optional third-party integrations may process or store data outside Salesforce and must be identified, reviewed, and approved separately.
What technologies are used?
GoldFinch uses Salesforce-native technologies, including:
- Salesforce Lightning Experience and Lightning Web Components
- Apex classes, triggers, scheduled jobs, and batch processing
- Salesforce Flow and approval processes
- Salesforce objects, files, reports, dashboards, and platform services
- JavaScript, HTML, and CSS for Lightning Web Components
- Salesforce metadata for configuration and deployment
Is middleware required?
No middleware is required for core GoldFinch functions. Middleware or external integration services, including MuleSoft or another integration platform, may be used when selected and licensed for a specific integration.
Is direct database access available?
No. Salesforce is a managed, multi-tenant service and does not provide customers with raw access to its underlying database. Authorized users and systems can retrieve data through Salesforce reports, SOQL, APIs, exports, and approved connectors, subject to configured security and platform limits.
Is database replication supported?
Not as direct replication of the underlying Salesforce database. A Salesforce Full Sandbox is a point-in-time environment for testing; it is not a high-availability or disaster-recovery replica. Downstream analytics or data replication can instead use Salesforce APIs, change events, scheduled exports, Microsoft Fabric, Data 360, or another approved design, subject to licensing and validation.
Integration and reporting
What integration methods are supported?
Depending on the business requirement, GoldFinch can participate in integrations using:
- Salesforce REST API
- Salesforce SOAP API
- Bulk API 2.0 for high-volume data movement
- Platform Events or Pub/Sub for event-driven integration
- Salesforce Flow or Apex callouts
- Scheduled, encrypted file exchange
- Salesforce Connect
- MuleSoft or another approved middleware product
The final design must identify the system of record, data mappings, volumes, frequency, latency, authentication, error handling, monitoring, reconciliation, and support ownership.
Can GoldFinch work with other applications in the same Salesforce org?
Yes. GoldFinch can work with Salesforce applications, including CRM and Nonprofit Cloud capabilities, in the same org through shared objects, relationships, Flow, Apex, Platform Events, and Salesforce APIs. The implementation must map the data model and preserve object-, field-, and record-level security.
How can data be used for reporting and analytics?
Customers can use Salesforce reports and dashboards, custom report types, SOQL, Salesforce APIs, scheduled exports, and approved business-intelligence connectors. Products such as Microsoft Fabric, CRM Analytics, Tableau, and Data 360 may provide additional capabilities and may require separate licensing.
Identity, access, and application security
What are the key security controls?
GoldFinch uses the security capabilities of the customer’s Salesforce environment. The final configuration can include:
- Salesforce tenant isolation and platform security controls
- HTTPS/TLS for data in transit
- Salesforce MFA or federated SSO
- Role-based and least-privilege access
- Profiles, Permission Sets, and Permission Set Groups
- Object-, field-, and record-level access controls
- Organization-wide defaults, roles, sharing rules, and restriction rules
- Approval workflows and segregation-of-duties controls
- Secure OAuth or certificate-based API authentication
- Login history, Setup Audit Trail, field history, and optional Event Monitoring
- Customer-controlled backup, retention, monitoring, and security configuration
- Customer-authorized, named, and time-limited support access
Does GoldFinch support SSO and MFA?
Yes. Salesforce supports federated SSO using standards such as SAML 2.0 and OpenID Connect, including integration with Microsoft Entra ID. Salesforce can enforce MFA through Salesforce or the customer’s identity provider. The customer should test provisioning, deprovisioning, group-to-permission mapping, conditional access, certificate rotation, and emergency-access procedures.
Does GoldFinch support role-based access and read-only users?
Yes. Salesforce Profiles and Permission Sets control application, object, field, and system permissions. Organization-wide defaults, roles, sharing rules, teams, and other sharing controls determine record visibility. Read-only users can be prevented from creating, editing, deleting, approving, posting, or administering data. Review report and export permissions separately because read access may still allow data extraction.
Can duties and critical functions be segregated?
Yes, through configuration and governance. Permission Sets, roles, sharing, approval steps, transaction permissions, and separate administrative responsibilities can segregate activities such as requesting, approving, receiving, adjusting, paying, posting, and administering the system. The customer should approve a segregation-of-duties matrix and test both permitted and prohibited access combinations.
Are audit trails available?
Yes, with scope limitations:
- Setup Audit Trail records many Salesforce configuration changes for 180 days.
- Field History Tracking or Field Audit Trail can record selected field changes with the user, timestamp, and old and new values.
- Login history and API or event data provide additional activity evidence.
- Event Monitoring and Transaction Security can support broader monitoring, alerts, and selected preventive actions when licensed and configured appropriately.
Field history records data changes; it does not automatically record every view of a sensitive field. Monitoring PII access, report exports, API use, or unusual activity may require Salesforce Shield/Event Monitoring, custom logging, or SIEM integration.
How are privileged users controlled?
Privileged Salesforce permissions can bypass ordinary sharing controls by design. Customers should minimize privileged accounts, separate administrative and daily-use identities, require strong MFA or SSO, use delegated administration where practical, restrict login context, monitor privileged activity, retain critical logs independently when required, and perform periodic access reviews.
How is customer support access controlled?
GoldFinch does not require a persistent remote-control agent on customer devices or servers. Access to a customer Salesforce org should occur only after customer authorization and should use named accounts, least-privilege permissions, MFA or SSO, time-bounded access, and auditable activity. The customer should revoke or expire access when the support case ends and should never provide shared credentials.
How is data encrypted?
Browser, mobile, and supported integration traffic uses HTTPS/TLS. Salesforce provides platform-level controls for protecting data at rest. Salesforce Shield Platform Encryption is an optional product that provides additional encryption and key-management capabilities. Each external integration must document its own encryption, credential, secret, and key-management controls.
Has GoldFinch experienced a security breach?
As of September 2, 2026, GoldFinch has not experienced a confirmed security breach affecting the GoldFinch application or customer data.
For this statement, “GoldFinch” means GoldFinch Cloud Solutions and the GoldFinch managed application, and “security breach” means confirmed unauthorized access to, acquisition of, or disclosure of GoldFinch-controlled systems or customer data. An authorized GoldFinch officer or security owner must review and approve this statement before reuse in a formal response.
Salesforce’s corporate or platform history should not be substituted for GoldFinch’s breach history. If an RFQ asks about material service providers or the underlying platform, address Salesforce separately and use current, authoritative Salesforce documentation.
Compliance and insurance
Is GoldFinch ISO certified?
GoldFinch is not independently ISO certified. Salesforce maintains ISO and other compliance certifications for covered Salesforce services. Salesforce certificates apply only to the services and scope named in each certificate and must not be presented as GoldFinch corporate certifications.
Before responding to an RFQ, verify that the cited Salesforce certificate is current and covers the Salesforce service included in the proposed architecture.
Does GoldFinch maintain cyber-liability insurance?
As of September 2, 2026, GoldFinch does not maintain a separate cyber-liability insurance policy. This answer is a corporate fact and must be reconfirmed with GoldFinch Finance or Legal before every formal response, as coverage may change.
Salesforce’s insurance, compliance, or contractual commitments do not constitute insurance coverage for GoldFinch.
Availability, backup, and recovery
How is high availability provided?
Salesforce provides core platform availability under the customer’s Salesforce agreement and applicable service architecture. Salesforce publishes service status and maintenance information through Salesforce Trust. GoldFinch availability depends on Salesforce availability, as described in the applicable GoldFinch agreement.
Do not create a separate GoldFinch uptime commitment unless the customer contract expressly approves it.
What are RTO and RPO?
- Recovery Time Objective (RTO) is the target time for restoring a service after an outage.
- Recovery Point Objective (RPO) is the maximum acceptable amount of data loss, expressed as a period of time.
For example, an RTO of four hours means the service is expected to be restored within four hours. An RPO of 24 hours means recovery may return the data to a point up to 24 hours before the incident.
What are GoldFinch’s RTO and RPO?
GoldFinch does not operate a separate hosting environment, runtime service, or database, so GoldFinch has no separate infrastructure-level RTO or RPO.
The effective RTO depends on Salesforce service recovery, the customer’s backup product, and the customer’s tested restoration procedures. The effective RPO depends primarily on backup frequency and retention. GoldFinch can assist with package or application-specific validation after restoration, but numeric commitments should be stated only after the Salesforce terms, backup architecture, responsibilities, and recovery runbook are contractually agreed and tested.
How are backups performed and restored?
Salesforce manages platform infrastructure resilience. Customers should also implement a logical data-protection plan appropriate to their requirements. Available options may include:
- Salesforce Recycle Bin for short-term recovery of eligible deleted records
- Salesforce Data Export for periodic extract files
- Salesforce Backup or an approved AppExchange backup product for scheduled or point-in-time recovery
- Separate versioning and backup of metadata and configuration
A Salesforce Sandbox is not a backup. The selected plan should define ownership, backup frequency, retention, encryption, restoration procedures, testing cadence, RTO, and RPO. Restoration testing should cover data, relationships, files, metadata, integrations, permissions, and post-restore reconciliation.
Where is the system hosted and where is the backup facility?
GoldFinch operates within the customer’s Salesforce org. The applicable Salesforce instance, infrastructure region, subprocessors, data residency, and resilience arrangements depend on the customer’s Salesforce service. Verify these details using Salesforce Trust and Compliance resources and the customer’s Salesforce agreement.
Devices, mobile use, and technical constraints
What browsers and devices are supported?
GoldFinch follows the current Salesforce Lightning Experience browser and device support policy. Desktop users should use a currently supported browser and operating system. Supported mobile workflows use the Salesforce mobile app or another specifically approved experience.
Validate scanner, handheld, tablet, camera, barcode symbology, label-printer language, printer driver, and direct-print combinations using the customer’s exact production hardware before purchase or deployment.
Is mobile access supported?
Yes, for GoldFinch pages and processes enabled and tested for the Salesforce mobile experience. Potential mobile functions include record lookup, approvals, dashboards, inventory inquiry, barcode-assisted receiving, picking, counting, transfers, task updates, and exception capture.
Complex administration, high-volume data maintenance, large reports, and planning consoles are normally better suited to desktop use unless specifically validated for mobile.
Does GoldFinch support offline operation?
Standard GoldFinch transaction processing requires an internet connection. Offline warehouse or financial transaction posting is not included by default. If offline execution is mandatory, it requires a separately designed, tested, licensed, and priced solution.
What other technical constraints should be disclosed?
- Direct access to the underlying Salesforce database is unavailable.
- Salesforce API, storage, and governor limits apply.
- Not every desktop workflow is optimized for phones.
- Scanner and label-printer compatibility requires hardware testing.
- Customer automation, integrations, and third-party packages can affect performance and release compatibility.
- A Full Sandbox is a test copy, not a backup or disaster-recovery replica.
Releases, testing, performance, and support
How often is GoldFinch updated?
GoldFinch’s standard schedule includes three cumulative managed-package updates per year. Interim packages may be provided when a critical fix or important enhancement cannot wait for the next cumulative update. Salesforce independently delivers its own seasonal platform releases.
Can customers test an update before Production deployment?
Yes. The standard process provides release notes, installs the candidate package in the customer’s Sandbox, allows customer validation, and obtains approval before deploying to Production. Customers should test their integrations, Flow automation, security model, reports, devices, and customer-specific extensions because these vary by Salesforce org.
How is application performance assessed?
There is no universal failure threshold for a Salesforce-native application. Capacity depends on the customer’s Salesforce edition and entitlements, data volume and distribution, record skew, automation, integrations, API allocations, synchronous transaction design, reports, devices, and Salesforce governor limits.
When an RFQ requests numeric benchmarks, provide only approved, reproducible evidence. Define the workload, data volume, concurrent users, ramp profile, response-time percentiles, failure criteria, monitoring, and error budget. Do not invent or generalize results from an unnamed customer.
What standard support is provided?
Standard support is included with an active GoldFinch subscription and covers verified defects in the standard application, questions about standard functionality, basic how-to guidance, and access to the Help Center. Configuration, training, data work, accounting consulting, third-party integrations, custom reporting or automation, custom development, and issues caused by customer-specific configuration are billable consulting services, subject to approval.
You can submit requests through the Customer Portal or email at any time. Standard active monitoring and response hours are Monday through Friday, 9:00 a.m. to 5:00 p.m. Eastern Time. Standard support does not promise active 24x7 response. You can arrange planned after-hours coverage, and it must be documented in the statement of work or support addendum.
Published initial-response targets are:
| Priority | Example | Initial-response target |
|---|---|---|
| Critical / P1 | Production unavailable or a critical process cannot continue without a reasonable workaround | 4 business hours |
| Standard / P2 | Defect, configuration assistance, or technical investigation | 1 business day |
| Low / P3 | How-to question, information request, documentation request, or enhancement request | 2 business days |
These are initial-response targets, not guaranteed resolution times. Resolution depends on the issue's nature and complexity.
RFQ submission checklist
Before reusing this article in a formal RFQ or RFP response, confirm:
- GoldFinch breach history and the reporting period
- Current cyber-insurance status and certificate, if applicable
- GoldFinch corporate certification status
- The scope and validity dates of any Salesforce compliance certificate
- Salesforce edition, licenses, instance, region, and contractual SLA
- Sandbox type, storage, refresh interval, ownership, and price
- Backup product, frequency, retention, encryption, restore tests, RTO, and RPO
- Shield, Event Monitoring, Platform Encryption, and SIEM requirements and licenses
- Named integrations, external data flows, and support ownership
- Supported devices, scanners, label printers, and proof-of-concept results
- Support hours, escalation process, training allowance, onsite services, and after-hours coverage
- Approved performance benchmarks and customer permission to reference them
- Any GoldFinch-specific contractual commitment not already stated in the standard agreement
References
- GoldFinch ERP FAQs
- GoldFinch Support Policy
- GoldFinch Package Upgrade Process
- GoldFinch Master Service Agreement
- Salesforce Trust
- Salesforce ISO compliance documentation
- Salesforce API documentation
- Salesforce security review guidelines
- Salesforce Lightning Web Components overview
- Salesforce data-access controls
- Salesforce password policies and MFA requirements
- Salesforce Field Audit Trail
- Salesforce Real-Time Event Monitoring and Transaction Security
- Salesforce backup and recovery options
- Salesforce supported browsers and devices
- Salesforce sandbox documentation
- Salesforce governor limits
Comments
0 comments
Please sign in to leave a comment.