Is your salesforce out of control? Secure your data, silence the alerts and cap your storage costs.

One unmonitored user account, an ignored security notice, or a loose third-party integration key or a member of staff clicking that link that thought was from another staff member. These actions can all expose your entire business to a catastrophic data breach. Backed by 16 years hands on Salesforce expertise, Zon projects acts as your dedicated Salesforce Security and Management partner - keeping yoru system airtight, advising you every step of the way whilst keeping your storage fees under control.

All for a simple, fixed monthly fee!

CRM platform management

You wouldn’t leave your commercial office front door unlocked overnight, nor would you manage the maintenance yourself, so why try and manage your CRM?

Backed by 18 years of hands-on Salesforce platform expertise, Zon Projects acts as your dedicated CRM security manager.

We act as your trusted Security and management of your core CRM and data and ensure that nothing slips through the net. Read about our range of services all tailored to keeping your Salesforce system secure.

Contact us and take advantage of our FREE Health Check, just complete the form below.

Are you besieged with messages and alerts from Salesforce?

Ignored System Warnings & Errors

  • Expiring identity certificates,

  • API version deprecations

  • Unhandled Flow Exceptions

  • Security alerts

  • Product retirements

  • Release management

These emails can land in unmonitored inboxes—left unacted upon until a core workflow or integration breaks without warning.

We can help. We will handle all of the incoming alerts from Salesforce™ on your behalf and deal with any updates required and will only bother you with the important questions.

Salesforce updates

Salesforce™ releases 3 new updates per year but it takes a lot of time getting up to speed with the changes. We will handle that for you and give you a summary updates for just the items that affect you.

Let us take the strain and deal with all the incoming messages. Complete our form and let’s arrange a short no obligation discussion.

Is your Salesforce storage overflowing?

are you Having to pay excessive storage charges for data you may not even need?

Storage

As your Salesforce Org matures you build up legacy data and there comes a time when the allocated storage starts running out. Most clients leave this to the point when they have already run over and are receiving emails from Salesforce to upgrade their plan. This style of storage is convenient but very expensive and will continue to increase as you do nothing about the underlying problem.

We recently helped a client who was at 213% of storage and on a countdown to a large bill. However, we assisted them in identifying records that were no longer needed in a live CRM and could be archived off to a simple csv file. We then developed an automated process that each days harvests off records of a defined age and this keep the storage limit in check.

If you are experiencing issues with Salesforce storage management, talk to us and let's see how we can also help you.

Salesforce MFA & Passkeys: What Has Changed?

  • Phishing-Resistant MFA is Now Mandatory for Admins: System Administrators and users with broad permissions (Modify All Data, View All Data, Customize Application) can no longer log in using standard SMS codes or standard authenticator pushes alone. Salesforce requires phishing-resistant verifiers—specifically Passkeys, built-in authenticators (Touch ID, Face ID, Windows Hello), or hardware keys (YubiKeys).

  • The "Passkey First" Login Screen: Users logging into direct UI or Single Sign-On (SSO) without a registered verifier are now prompted to register a Passkey by default.

  • SSO Signal Verification: If your team logs in via an Identity Provider (IdP) like Azure AD/Entra ID or Okta, Salesforce actively audits the Authentication Method Reference (AMR) signal. If your SSO provider fails to pass a phishing-resistant signal, privileged users risk getting locked out

If you need help with the new security changes, talk to us. We helped several companies manage the changes including those that used a Single Sign System or had hundred of outworkers.

Contact us below to have a conversation about any issues you may be experiencing.

The Shared Responsibility Trap

Why MFA Enforcement Doesn't Prevent Data Breaches

Many UK SMEs and charities assume that because Salesforce enforces login security at the front door, their customer data is completely safe. Under UK GDPR and the Cloud Shared Responsibility Model, this is a dangerous misconception. Most data breaches occur not through technical failure, but because of humans. Whether that is not selecting secure passwords, or leaving their PC logged in whilst away from a desk, or being duped by someone external into sharing login details.

The other huge culprit is external integrations. So Apps that you have connected using a simple Oauth login handshake or where you have installed and used a full licence to allow access. These are silent connections that once infiltrated, can open up all of your data to bad actors. Maybe you are unaware, but could a previous employee have added some applications like this and no-one has checked them?

That is where we come in. We can run a Health Check on your system and identify these security risks. Simply complete the form and we will contact you to arrange a quick security Health check!

Avoiding Data Breaches

How We Lock Down Your Salesforce Security

Through our Platform Guard and Managed Operations retainers, Zon Projects closes the security gap so you remain fully compliant without getting locked out:

  • Identity Hardening & Username Obfuscation: Decoupling Salesforce usernames from public staff email addresses to prevent credential-harvesting attacks.

  • Passkey & SSO Alignment: Configuring correct Identity Provider signals (AMR/ACR) and enforcing passkey policies across all privileged roles.

  • Integration License Migration: Shifting connected apps off full-price System Admin seats onto restricted, cost-effective API-only licenses.

  • Quarterly Security & Access Audits: Systematic health checks benchmarked against native Salesforce security baselines and Cyber Essentials access rules.

Salesforce Secures the Building; You Own the Keys:

Salesforce guarantees that their cloud servers are hardened. However, if your team assigns full System Admin credentials to third-party integration apps, leaves public work emails as usernames, or fails to deauthorize departing employees within an hour, your organisation remains 100% legally liable for any resulting data breach.

Permission Creep & Over-Privileged Users: Assigning broad administrative rights to standard staff members accidentally subjects them to strict Phishing-Resistant MFA rules while exposing your sensitive customer records to internal visibility leaks.

Uncover Your System Security Posture in 15 Minutes

Request a complimentary Salesforce Security & Exposure Audit. We inspect your org for passkey readiness, identity exposure, over-privileged users, and integration risks—delivering a 2-page Executive Risk Scorecard within 48 hours.

Our packages

CRM Caretaker
£495.00

Essential Alert Management & System Insurance

The entry-level solution for organizations that need system noise eliminated and basic user access secured.

  • Proactive Error & Alert Interception: We capture and fix unhandled Flow exceptions, certificate warnings, and API deprecation notices before they disrupt your staff.

  • 1-Hour User Offboarding SLA: Guaranteed rapid access revocation protocols to safeguard customer data whenever an employee departs.

  • Tri-Annual Release Management: Sandbox testing and patch reviews prior to major seasonal Salesforce updates (Spring, Summer, Winter).

  • Storage & License Oversight: Monthly tracking of storage thresholds and active user seats to prevent surprise overage bills.

CRM Guard
£995.00

Data Breach Defense, Identity Hardening & Compliance

For data-conscious organizations needing robust security, passkey enforcement, and UK GDPR / Cyber Essentials alignment.

Includes Everything in Level 1 (Platform Care), PLUS:

  • Identity Obfuscation & Passkey Enforcement: Decoupling CRM usernames from public staff email addresses to block brute-force and credential-harvesting attacks.

  • Integration License Migration: Moving connected apps (Xero, website forms, email marketing) off expensive System Admin seats onto restricted, cost-effective API licenses.

  • Quarterly Security Health Audits: Systematic health checks benchmarked against native Salesforce security standards and UK compliance rules.

  • Breach Forensics & Incident SLA: Rapid access-log extraction and audit reporting ready for your Data Protection Officer (DPO).

Book a call with us and discuss any aspects of our packages or any other Salesforce security related requirements. Just complete our simple form and we will get in touch!

CRM Managed
£1,950.00

Your Complete Outsourced CRM Department

Delivers the full operational output of an in-house £60k/year Salesforce Administrator at less than half the cost.

Includes Everything in Level 2 (Platform Guard), PLUS:

  • Desktop Admin Support Queue: SLA-backed execution of day-to-day configuration requests (new fields, page layouts, custom reports, dashboards, and Flow updates).

  • Automated Storage Management: Deployment of our proprietary storage management software to archive historical records, clear orphaned files, and permanently cap storage fees.

  • Pre-Release Sandbox Testing: Complete environment testing in dedicated sandboxes prior to major Salesforce updates.

  • Strategic Account Governance: Structured monthly reviews to ensure your CRM directly supports business growth.

Are you sure all your ex-employees are locked out of your system?

Or did you expect someone else to close their access on the day they left the company? This is something we see many times, staff who left the company months ago still having access to a clients crm! Who is responsible? We can manage this for you and setup a process to add leaving date automations to close the access. We can also ensure that all records are transferred to an appropriate member of staff which avoids open discussions being missed!!

If you require this type of service, please complete our form below and we will be pleased to discuss this with you.

Licence & Staff management

Out of Hours Support

We understand that things go wrong in the evenings and at weekends. That’s why we aim to support you in times of crisis. We offer extended support hours to our customers as part of our packages so you can rest easy. Contact us to discuss any requirements you may have.

Just click the link below

Partnerships with MSP’s

Uncover Your Clients' Hidden Salesforce Risks in 15 Minutes

Unmonitored Salesforce orgs are the largest SaaS security loophole in your clients' environments. Partner with Zon Projects to protect their Cyber Essentials standing, eliminate system error noise, and generate high-margin recurring revenue—without adding a single penny to your payroll.

  • Zero Payroll Risk: Deliver certified, application-layer CRM governance without hiring a £60k/year in-house specialist.

  • Flexible Margins: Earn a 10–15% recurring monthly referral commission or white-label our services directly into your master agreements.

  • Actionable Exposure Scorecard: We audit your client's org against Cyber Essentials access rules, identity risks, and storage limits—delivering a co-branded 2-page report within 48 hours.

We will do this for FREE, just complete the form below!