Frequently asked questions
What a scan reads, what it never touches, what a report covers, and how billing works. silobase reads Salesforce metadata only — it never reads your data and never sends email.
What does a scan actually read?
Metadata only. silobase parses your flows, workflow rules, email alerts, Apex senders, and org-wide deliverability settings from a metadata export you upload. It never reads email content, CRM records, or contact data — and nothing is ever written back to your org.
Will silobase ever send email from my org?
No. The scanner is strictly read-only. It maps every path that would send email if triggered — it never triggers one. The blast-radius manifest is a static analysis of your automation metadata, not a live test.
What counts as an org?
Each Salesforce environment with its own org ID — a full sandbox, partial sandbox, developer org, or production. Free and Report cover one org at a time. Ledger covers unlimited orgs, so you can track every sandbox alongside the production org it refreshes from.
Is the $99 report really one-time?
Yes. One payment covers one org for one release cycle: the full manifest, safe-test plan, deliverability checklist, and the PDF + CSV evidence export, which are yours to keep forever. It also includes free rescans for 14 days so you can verify fixes before sign-off.
What is the refund policy?
The report carries a 14-day full refund: if the manifest surfaces nothing beyond what the free scan already showed you, email us and we refund the $99, no questions. The ledger can be cancelled anytime — billing stops at the end of the current cycle and there are no cancellation fees.
How fast can I scan after a sandbox refresh?
Right after the refresh. Upload a fresh metadata export and the detector runs immediately — no live-org connection or waiting required. On the Ledger plan you can rescan every release and compare it against the previous run before anyone starts UAT.