Is your salesforce out of control? Secure your data, silence the alerts and cap your storage costs.

One unmonitored user account, an ignored security notice, or a loose third-party integration key or a member of staff clicking that link that thought was from another staff member. These actions can all expose your entire business to a catastrophic data breach. Backed by 16 years hands on Salesforce expertise, Zon projects acts as your dedicated Salesforce Security and Management partner - keeping yoru system airtight, advising you every step of the way whilst keeping your storage fees under control.

All for a simple, fixed monthly fee!

Glass building entrance with a security officer unlocking the door, digital overlay of Salesforce CRM security management and health check interfaces, and a web form titled 'Contact us for a FREE Health Check'.

CRM platform management

You wouldn’t leave your commercial office front door unlocked overnight, nor would you manage the maintenance yourself, so why try and manage your CRM?

Backed by 18 years of hands-on Salesforce platform expertise, Zon Projects acts as your dedicated CRM security manager.

We act as your trusted Security and management of your core CRM and data and ensure that nothing slips through the net. Read about our range of services all tailored to keeping your Salesforce system secure.

Contact us and take advantage of our FREE Health Check, just complete the form below.

Are you besieged with messages and alerts from Salesforce?

Multiple overlapping screenshots of emails and notifications related to product and service updates, security alerts, and certification changes, with a background illustration of a forest and mountains.

Ignored System Warnings & Errors

  • Expiring identity certificates,

  • API version deprecations

  • Unhandled Flow Exceptions

  • Security alerts

  • Product retirements

  • Release management

These emails can land in unmonitored inboxes—left unacted upon until a core workflow or integration breaks without warning.

We can help. We will handle all of the incoming alerts from Salesforce™ on your behalf and deal with any updates required and will only bother you with the important questions.

Salesforce updates

Salesforce™ releases 3 new updates per year but it takes a lot of time getting up to speed with the changes. We will handle that for you and give you a summary updates for just the items that affect you.

Let us take the strain and deal with all the incoming messages. Complete our form and let’s arrange a short no obligation discussion.

Is your Salesforce storage overflowing?

are you Having to pay excessive storage charges for data you may not even need?

A digital dashboard showing storage usage statistics with data categories, used and available storage, and percentages.

Storage

As your Salesforce Org matures you build up legacy data and there comes a time when the allocated storage starts running out. Most clients leave this to the point when they have already run over and are receiving emails from Salesforce to upgrade their plan. This style of storage is convenient but very expensive and will continue to increase as you do nothing about the underlying problem.

We recently helped a client who was at 213% of storage and on a countdown to a large bill. However, we assisted them in identifying records that were no longer needed in a live CRM and could be archived off to a simple csv file. We then developed an automated process that each days harvests off records of a defined age and this keep the storage limit in check.

If you are experiencing issues with Salesforce storage management, talk to us and let's see how we can also help you.

Salesforce MFA & Passkeys: What Has Changed?

  • Phishing-Resistant MFA is Now Mandatory for Admins: System Administrators and users with broad permissions (Modify All Data, View All Data, Customize Application) can no longer log in using standard SMS codes or standard authenticator pushes alone. Salesforce requires phishing-resistant verifiers—specifically Passkeys, built-in authenticators (Touch ID, Face ID, Windows Hello), or hardware keys (YubiKeys).

  • The "Passkey First" Login Screen: Users logging into direct UI or Single Sign-On (SSO) without a registered verifier are now prompted to register a Passkey by default.

  • SSO Signal Verification: If your team logs in via an Identity Provider (IdP) like Azure AD/Entra ID or Okta, Salesforce actively audits the Authentication Method Reference (AMR) signal. If your SSO provider fails to pass a phishing-resistant signal, privileged users risk getting locked out

If you need help with the new security changes, talk to us. We helped several companies manage the changes including those that used a Single Sign System or had hundred of outworkers.

Contact us below to have a conversation about any issues you may be experiencing.

The Shared Responsibility Trap

Why MFA Enforcement Doesn't Prevent Data Breaches

Many UK SMEs and charities assume that because Salesforce enforces login security at the front door, their customer data is completely safe. Under UK GDPR and the Cloud Shared Responsibility Model, this is a dangerous misconception. Most data breaches occur not through technical failure, but because of humans. Whether that is not selecting secure passwords, or leaving their PC logged in whilst away from a desk, or being duped by someone external into sharing login details.

The other huge culprit is external integrations. So Apps that you have connected using a simple Oauth login handshake or where you have installed and used a full licence to allow access. These are silent connections that once infiltrated, can open up all of your data to bad actors. Maybe you are unaware, but could a previous employee have added some applications like this and no-one has checked them?

That is where we come in. We can run a Health Check on your system and identify these security risks. Simply complete the form and we will contact you to arrange a quick security Health check!

A person with a wedding ring is using their right hand to tap on a computer screen, which displays a login screen for Salesforce. A finger with no ring is touching the computer.

Avoiding Data Breaches

Collection of news articles about cybersecurity breaches and data theft related to Salesforce, including headlines, images of digital security themes, and cityscapes.

How We Lock Down Your Salesforce Security

Through our Platform Guard and Managed Operations retainers, Zon Projects closes the security gap so you remain fully compliant without getting locked out:

  • Identity Hardening & Username Obfuscation: Decoupling Salesforce usernames from public staff email addresses to prevent credential-harvesting attacks.

  • Passkey & SSO Alignment: Configuring correct Identity Provider signals (AMR/ACR) and enforcing passkey policies across all privileged roles.

  • Integration License Migration: Shifting connected apps off full-price System Admin seats onto restricted, cost-effective API-only licenses.

  • Quarterly Security & Access Audits: Systematic health checks benchmarked against native Salesforce security baselines and Cyber Essentials access rules.

Salesforce Secures the Building; You Own the Keys:

Salesforce guarantees that their cloud servers are hardened. However, if your team assigns full System Admin credentials to third-party integration apps, leaves public work emails as usernames, or fails to deauthorize departing employees within an hour, your organisation remains 100% legally liable for any resulting data breach.

Permission Creep & Over-Privileged Users: Assigning broad administrative rights to standard staff members accidentally subjects them to strict Phishing-Resistant MFA rules while exposing your sensitive customer records to internal visibility leaks.

A presentation slide titled "The CRM Shared Responsibility Model" comparing Salesforce security measures and organizational ownership responsibilities. It lists Salesforce secure infrastructure, data protection, MFA, platform encryption versus organizational permissions, user roles, API security, and GDPR compliance.

Uncover Your System Security Posture in 15 Minutes

Request a complimentary Salesforce Security & Exposure Audit. We inspect your org for passkey readiness, identity exposure, over-privileged users, and integration risks—delivering a 2-page Executive Risk Scorecard within 48 hours.

Our packages

CRM Caretaker
£495.00

Essential Alert Management & System Insurance

The entry-level solution for organizations that need system noise eliminated and basic user access secured.

  • Proactive Error & Alert Interception: We capture and fix unhandled Flow exceptions, certificate warnings, and API deprecation notices before they disrupt your staff.

  • 1-Hour User Offboarding SLA: Guaranteed rapid access revocation protocols to safeguard customer data whenever an employee departs.

  • Tri-Annual Release Management: Sandbox testing and patch reviews prior to major seasonal Salesforce updates (Spring, Summer, Winter).

  • Storage & License Oversight: Monthly tracking of storage thresholds and active user seats to prevent surprise overage bills.

CRM Guard
£995.00

Data Breach Defense, Identity Hardening & Compliance

For data-conscious organizations needing robust security, passkey enforcement, and UK GDPR / Cyber Essentials alignment.

Includes Everything in Level 1 (Platform Care), PLUS:

  • Identity Obfuscation & Passkey Enforcement: Decoupling CRM usernames from public staff email addresses to block brute-force and credential-harvesting attacks.

  • Integration License Migration: Moving connected apps (Xero, website forms, email marketing) off expensive System Admin seats onto restricted, cost-effective API licenses.

  • Quarterly Security Health Audits: Systematic health checks benchmarked against native Salesforce security standards and UK compliance rules.

  • Breach Forensics & Incident SLA: Rapid access-log extraction and audit reporting ready for your Data Protection Officer (DPO).

A woman smiling while working on a laptop at a desk in a bright room with large windows, showing Salesforce dashboards on the screen and a coffee mug beside the laptop.

Book a call with us and discuss any aspects of our packages or any other Salesforce security related requirements. Just complete our simple form and we will get in touch!

Man working on a laptop with Salesforce Security Health Check displayed, surrounded by multiple monitors in an office setting.
CRM Managed
£1,950.00

Your Complete Outsourced CRM Department

Delivers the full operational output of an in-house £60k/year Salesforce Administrator at less than half the cost.

Includes Everything in Level 2 (Platform Guard), PLUS:

  • Desktop Admin Support Queue: SLA-backed execution of day-to-day configuration requests (new fields, page layouts, custom reports, dashboards, and Flow updates).

  • Automated Storage Management: Deployment of our proprietary storage management software to archive historical records, clear orphaned files, and permanently cap storage fees.

  • Pre-Release Sandbox Testing: Complete environment testing in dedicated sandboxes prior to major Salesforce updates.

  • Strategic Account Governance: Structured monthly reviews to ensure your CRM directly supports business growth.

Two professionals, a man and a woman, having a conversation in a meeting room with a laptop displaying the Salesforce logo and funnel chart, sunlight coming through large windows.
Screenshot of a report titled 'New Contacts & Accounts Report' showing a table with contact details, including names, addresses, phone numbers, and email addresses, with a pop-up window for exporting data in Excel format.

Are you sure all your ex-employees are locked out of your system?

Or did you expect someone else to close their access on the day they left the company? This is something we see many times, staff who left the company months ago still having access to a clients crm! Who is responsible? We can manage this for you and setup a process to add leaving date automations to close the access. We can also ensure that all records are transferred to an appropriate member of staff which avoids open discussions being missed!!

If you require this type of service, please complete our form below and we will be pleased to discuss this with you.

Licence & Staff management

Screenshot of an online shopping page featuring various software products with descriptions, prices, quantity selectors, and 'Add to Cart' buttons.
Screenshot of a software interface displaying company license information organized in tables, including user licenses, permission set licenses, and feature licenses. The table includes columns for license names, statuses, total licenses, used licenses, remaining licenses, expiration dates, and additional details.

Out of Hours Support

We understand that things go wrong in the evenings and at weekends. That’s why we aim to support you in times of crisis. We offer extended support hours to our customers as part of our packages so you can rest easy. Contact us to discuss any requirements you may have.

Just click the link below

Partnerships with MSP’s

The Application-Layer Security Blind Spot in Your Client Base

As a UK IT Managed Service Provider, you secure your clients' network infrastructure, manage Microsoft 365, and maintain their Cyber Essentials accreditation. However, when your clients run Salesforce without a dedicated administrator, a massive security loophole opens up inside your managed environment.

Unmonitored Salesforce orgs frequently contain default usernames matching public emails, loose third-party API permissions, and un-offboarded former staff. If a data breach occurs through an unmanaged CRM, your client won't blame Salesforce—they will ask why their IT partner didn't flag the exposure.

Zon Projects acts as your specialist Salesforce application partner, closing the CRM security gap and creating a new recurring revenue stream for your business.

  • Zero Payroll Overhead: Deliver certified, enterprise CRM governance and error monitoring without adding a £60,000/year specialist to your payroll.

  • Cyber Essentials & GDPR Protection: Eliminate unmonitored SaaS access risks, enforce passkey security, and lock down API integrations across your client base.

  • Flexible Revenue Models: Earn a 10–15% recurring monthly referral commission for the lifetime of the client contract, or white-label our governance packages directly into your master agreements to increase your Average Revenue Per User (ARPU).

  • Free Executive Risk Audits: We run a complimentary 15-minute diagnostic on your target clients' orgs, providing a co-branded 2-page Executive Risk Scorecard that uncovers hidden identity vulnerabilities, loose API seats, and storage bloat.

Explore the Partner Program with us.

Three diverse business professionals in formal attire working with holographic puzzle pieces and digital graphics related to Salesforce, Microsoft, and cybersecurity in a high-tech conference room.