Discover context
Find personal data across the Salesforce estate and understand the records involved.
For risk and privacy
POCAVI brings discovery, controlled action, sandbox protection, and operational evidence together for the people accountable for Salesforce data.
The operating rhythm
Start with the responsibility your team already owns. POCAVI gives it a more connected route from signal to action.
Find personal data across the Salesforce estate and understand the records involved.
Use masking and sandbox checks to reduce exposure while teams continue to work.
Run subject-access, deletion, anonymisation, and breach workflows with a clear record.
Keep the operating context needed to explain the work to the people who need to review it.
POCAVI Compliance
Explore the product depth behind this workflow, then expand when shared Salesforce context makes the next decision better.
Explore ComplianceRisk, privacy and compliance teams
A subject access request means finding personal data across objects nobody has mapped, deciding what to redact, and then proving afterwards that it was all done properly.
What changes
Discovery runs across standard objects, custom objects with PII fields, files and email records, in every connected org rather than one at a time.

What changes
Format-preserving masking means a sandbox behaves like production without being it. Names tokenised, emails masked, referential integrity intact.

What changes
Each erasure produces a record of systems processed, locations covered, records deleted and any overrides, exportable as a document a reviewer can keep.

Capabilities
Compliance gives the team a practical route through the work that becomes urgent only when it has been left too long.

Data Masking and Sandbox Checks Masks personal data while preserving relationships and identifies live PII or unsafe configuration in sandbox environments.
Sandbox Compliance Detects live PII, unsafe email deliverability, production endpoints, and stale sandbox risk.
Restorable Privacy Actions Snapshots original values before GDPR actions and provides a 30-day restore window.
Public Link Audit and File Content Scanner Finds public shared links and scans uploaded files for personal data across text, PDFs, spreadsheets, documents, and images.
PII Data Map Inventories PII fields by org with records-with-data counts and risk assessment.
DPIAs, Breach Workflow, and Register Supports DPIAs, processing records, breach response, and the evidence around privacy decisions.
Deletion Proof Cross-checks Salesforce and the audit record to provide a signed confirmation of erasure.
Questions
The workflows are built around subject rights, breach timelines and processing records, which map to GDPR and to most equivalent regimes.
Yes. Masking preserves format and referential integrity, so relationships between records survive and test scenarios still run.
Systems processed, data locations covered, records deleted, retention overrides and issues, with timestamps, exportable as JSON.
Read next
The product behind this
Discover, protect, respond, govern, and prove.