The short version. Routing Forensics can read your CRM and can change nothing in it. That is checked before every run, and the run stops if the check fails. Your records are read to be counted, then dropped. You can disconnect at any time.
What it can read in Salesforce
Your admin connects it as a user holding our read-only permission set, installed as a Salesforce connected app that only that user is pre-authorised to use. The permission set grants:
| Access | What |
|---|---|
| Read, with view all records | Lead, Contact, Account, Opportunity, Campaign, Campaign Member |
| Read on named fields | For example lead source and email, the opportunity's account and amount, and which record a task or event belongs to |
| System | API access, view setup and configuration, view roles |
| Create, edit, delete | None, on any object |
View all records is what makes the counts complete: a lead the user cannot see is a lead the check cannot count.
What is checked before every run
That the user can read leads and setup; that it cannot create, edit or delete Leads, Campaigns or Opportunities; and that it holds none of Modify All Data, Modify Metadata, Customize Application or Author Apex. If any of that is not true, nothing is read.
Routing tools and HubSpot
- LeanData and Traction Complete keep their logs and settings in Salesforce objects. Your admin adds read access to those objects to the same permission set; nothing else changes.
- HubSpot connects with read-only scopes for contacts and owners. HubSpot's workflow permission has no read-only version, so we never ask for it: your admin exports the workflows with their own key, which never reaches us.
What is kept, and for how long
- Kept: counts, per-person response figures (names and medians, for your team's own view), and each finding with the query that proves it.
- Never kept: lead, contact or opportunity records. They are read during a run to be counted, then dropped.
- How long: results are kept for 13 months unless you choose otherwise, and older ones are deleted automatically. When an account closes, its data is deleted within 30 days.
How it is protected
- CRM connection tokens are encrypted, with the key kept apart from the database.
- Sign-in is by a single-use email link, and sign-in tokens are stored only as hashes.
- Disconnecting cancels the login at your CRM and deletes the stored token at once.
Who else handles data
- Resend (Ireland) sends sign-in and alert emails.
- Cloudflare serves this website and counts visits to it, without cookies. It never carries your CRM data.
- Hosting for the service is confirmed, and named here, before sign-ups open.
The free scan
The free scan runs entirely in your browser. The export you drop on it is never uploaded, stored or sent to us.
Security questions: hello@routingforensics.com. How we handle personal data: privacy notice.
Read-only, and proven every night.
Routing Forensics connects as a read-only user and checks your routing against your real leads every night. Register interest and you will be first to get a free health report.
Or check it now: the free scan finds routing configuration defects in your Salesforce or HubSpot workflow export, in your browser, and nothing is uploaded.
More about Routing Forensics
- Every check is proven on real Salesforce before it reaches you.
- The lead routing health checklist.
- Works with the systems your leads actually run through.
- Your router's audit log records what it did. Not what it missed.
- A Salesforce report shows what matches. Not what is broken.
- An audit is a photograph. Routing changes every week.