If you're the security reviewer for a Salesforce org, you want short, precise answers: does this app add new users or a managed package, where do documents and credentials live, and how do you verify signer identity? Savvy DocuGen is built around one clear idea: templates and document generation happen from your Salesforce records, and signatures are sent using your own Circularo account—so you keep control of the signature flow and the resulting signed PDFs.
Salesforce e-signature security: connection and data flow
Here is the flow you need to see to sign off. Savvy DocuGen fills Word or PDF templates from any Salesforce record (standard or custom) and then sends the document for signature using the customer's Circularo account. When the document is signed, the signed PDF is written back to the same Salesforce record.
- No managed package to install. Connects through an authorised connection, so there is nothing for a security team to review.
- Templates pull data directly from the Salesforce record you point at—fields on Account, Opportunity, Contract, Contact or custom objects—so the data never needs to be exported to a separate system before signing.
- Signed documents are stored on the Salesforce record, using either Salesforce Files or Notes & Attachments depending on the template configuration.
Why this matters: because the signature send happens from your Circularo account, the email delivery and signer interaction run under your vendor relationship. The finished signed PDF lands in your Salesforce org where your existing sharing model, retention and backup apply.
Signer authentication: options you can enforce
Signer identity is often the sticking point for compliance teams. Savvy DocuGen supports two practical controls you can require per signer:
- An emailed one-time code the signer must enter to proceed.
- A per-signer password that is read from a field on that signer's Salesforce record.
Use them separately or together. For example, set OTP-only for low-risk approvals and OTP-plus-password for high-value contracts. Because the password is read from the Contact or a custom signer object in Salesforce, you control password rotation and storage with your org's policies.
Practical example
Imagine a team sending 200 renewals a month where each agreement is 60 pages and requires two signers. Without clear authentication the business spends four days chasing signatures and auditing who signed what. Turn on emailed OTP for all signers and a per-signer password for the counterparty, send via your Circularo account, and the signed PDF is automatically archived back on the Opportunity or Contract record. Your compliance team can then review the signed file and Salesforce sharing records rather than chasing emails.
Document storage in Salesforce: Files vs Notes & Attachments
Two things security teams check first: file size limits and access controls. Savvy DocuGen writes the finished document back to the record and supports both storage targets:
- Salesforce Files: allows documents up to 40 MB and uses the Files sharing model and ContentDocument visibility controls.
- Notes & Attachments: capped at 25 MB by Salesforce and cannot be raised; use it only for smaller documents or legacy processes.
Recommendation: choose Files for anything over a few megabytes and for orgs that rely on ContentDocumentLink controls. The signed PDF sits in your org, so standard audit and backup processes apply.
Signature positions and document integrity
One frequent complaint is that signatures shift when a document repaginates. Savvy DocuGen places signature fields using anchor tags embedded in the Word/PDF templates so positions survive repagination. In practice you put an anchor in the template where you want the signature to appear and the engine finds that anchor at runtime.
{{SIGN_HERE_signer1}}
That example is a simple anchor you might place in a Word template. The platform resolves the anchor during merge and places the signature box relative to it rather than fixed coordinates. That reduces layout breakage for multi-page documents and keeps the signature where reviewers expect it to be.
Checklist for a security review
Walk through this with your team and you'll cover the main concerns quickly.
- Connection: confirm the authorised connection is created by your admin. No managed package is installed in your org.
- Vendor account: verify the Circularo account sending signatures is under your contract and review its audit logs.
- Signer authentication: decide which signers need OTP, and which need a per-signer password field in Salesforce.
- Storage: pick Files for documents likely to exceed 25 MB and confirm sharing rules apply to saved signed PDFs.
- Audit trail: verify the signed PDF is written back to the related Salesforce record and that your org's field-history and event-logging meet your compliance needs.
What this means operationally
For an IT or security reviewer the key takeaways are simple. The document generation runs in your org against your records. The signing flow runs under your Circularo account. The signed file comes back into your Salesforce record where your access, retention and backup policies apply. You do not install a managed package, and the connection is an authorised connection you create during setup.
If you want to validate this end-to-end, try a realistic test in a sandbox: generate a 60-page template, send it through your Circularo account with OTP enabled, and check the signed PDF lands on the Opportunity or Contract record with the correct sharing. Savvy DocuGen works in sandboxes exactly as in production, so you can run the full security checklist without touching production.
Ready to test it? Try Savvy DocuGen in your sandbox and run the security checklist above.
Read next