Pocavi Compliance

Discover, protect, respond, govern, and prove.

Privacy and compliance operations for Salesforce teams that need to handle personal data responsibly and leave a reliable evidence trail behind the work.

A subject access request moving through collect, review and export, each step marked complete
10Compliance capabilities
72-hourBreach workflow with owners
EveryAction keeps evidence
FormatPreserving data masking

Capabilities

Make privacy operations a repeatable process.

Compliance gives the team a practical route through the work that becomes urgent only when it has been left too long.

  • GDPR SAR AutomationFinds a person across Salesforce, guides deletion or anonymisation, and retains an audit trail for the action.
  • SAR Dashboard and Data PortabilityTracks requests as cases, drafts responses, exports a person's data, and keeps the audit record.
  • Consent and Retention ManagementAssesses consent maturity and checks retention policies, overdue records, and conflicts.
A deletion record covering 12,842 records across six systems with exportable evidence

Data Masking and Sandbox Checks Masks personal data while preserving relationships and identifies live PII or unsafe configuration in sandbox environments.

Sandbox Compliance Detects live PII, unsafe email deliverability, production endpoints, and stale sandbox risk.

Restorable Privacy Actions Snapshots original values before GDPR actions and provides a 30-day restore window.

Public Link Audit and File Content Scanner Finds public shared links and scans uploaded files for personal data across text, PDFs, spreadsheets, documents, and images.

PII Data Map Inventories PII fields by org with records-with-data counts and risk assessment.

DPIAs, Breach Workflow, and Register Supports DPIAs, processing records, breach response, and the evidence around privacy decisions.

Deletion Proof Cross-checks Salesforce and the audit record to provide a signed confirmation of erasure.

See all 10 compliance capabilities

Compliance

Mask what matters, keep what is useful

Format-preserving masking, so the data still behaves like data. The rules are explicit and the policy is versioned.

Personal data before and after masking, with three rules applied to email, phone and date of birth while preserving format

Compliance

The 72 hours, with owners

Assess, contain, review, notify. Each with a name against it and the clock visible to everyone.

A 72-hour breach response timeline at hour 54 with 18 hours remaining, four steps each with a named owner

Compliance

Prove the deletion happened

Six systems, eighteen locations, no retention overrides, no issues. Exported as evidence you can hand to a regulator.

A deletion record showing 12,842 records removed across 6 systems and 18 data locations, with an exportable evidence document

Compliance

Find the links nobody remembered sharing

Public links go stale and stay live. Pocavi finds them and revokes them.

An audit of three public file links, two safe and one pricing sheet with public access detected and an option to revoke it

The workflow

How the work actually runs

01Discover

Find a person across Salesforce objects using email, name, or phone, including multi-org search where needed.

02Protect

Identify personal data, use relationship-aware masking in sandboxes, and run compliance checks against live PII.

03Respond

Guide SARs, deletion, anonymisation, and breach workflows with consistent action and a full record.

04Prove

Maintain a processing register, DPIAs, evidence, and the context required for an accountable response.

Integrations

Compliance work reaches the whole estate

Personal data does not stay in one object, so discovery does not either.

All integrations
  • SalesforceStandard and custom objects, files, and email records.
  • SandboxesCheck and mask non-production copies before they are shared.
  • WebhooksRaise a request or an incident from your existing intake.
  • Evidence exportSigned JSON output a reviewer can keep.

Security

Evidence is the product, not a by-product

A regulator asks what you did and when. Every workflow answers that by default.

Security overview
  • Each SAR, DPIA and erasure keeps a step-by-step record.
  • Masking is format-preserving, so test data stays useful.
  • Deletion produces an exportable evidence document.
  • Sandbox checks run before a refresh, not after a leak.

Questions

Before you book a demo

Where does person discovery look?

Standard objects, custom objects with PII fields, files, and email records, across every connected org rather than one at a time.

Is masked data still usable for testing?

Yes. Masking preserves format and referential integrity, so the data behaves like production without being it.

What evidence does an erasure produce?

A record of systems processed, locations covered, records deleted and any retention overrides, exportable as a document.

Does this cover GDPR only?

The workflows are built around subject rights, breach timelines and processing records, which map to GDPR and to most equivalent regimes.

Read next

Go deeper on the job itself

Pricing

Compliance is $799/estate/mo

per Salesforce estate / month. Bundle it with the products next to it and the price comes down.

The rest of the platform

They work better together.