You need a concise answer for your security review: where do generated documents and e-signatures live, who can access them, and what external services are involved. You also want the implications for storage limits, retention and automated triggers.
Where the generated Salesforce documents are stored
When Savvy DocuGen produces a document from a Word or PDF template, the finished file is written back to the Salesforce record you triggered it from. That means the document lives in Salesforce Files or in Notes & Attachments depending on the template configuration.
What that means for access control
- Files written to a record inherit your org’s object sharing and file visibility settings — they do not bypass Salesforce security model.
- If you store the output in Notes & Attachments, remember Salesforce caps those files at 25 MB per file; larger outputs must use Files.
- Signed PDFs are also written back to the same record, so signature copies are stored inside Salesforce under the same access rules.
Practical check: if you have a 60-page agreement merged from Opportunity and several Quote line items, and the resulting PDF is 30 MB, configure the template to save to Files. Notes & Attachments will silently fail for files over 25 MB because of Salesforce limits — that’s an admin decision, not a DocuGen behaviour.
How e-signatures in Salesforce are handled and written back
Savvy DocuGen sends signature requests through your organisation’s own Circularo account. The signature ceremony runs through Circularo; after signing, the signed PDF is returned and saved to the originating Salesforce record.
Implications for data residency and third-party access
- Document generation reads fields from Salesforce records (standard and custom) to populate templates. The output file is persisted back to Salesforce.
- The signature interaction itself happens in Circularo under your account — if your security policy restricts which signing providers you can use, Circularo must be on that approved list.
- No persistent copies of the signed file are kept outside Salesforce by Savvy DocuGen; the signed PDF is written back to your org and subject to your retention and backup policies.
Signer identity and verification
You can require an emailed one-time code for signer identity, and DocuGen can also check a per-signer password stored in that signer’s Salesforce contact or user record before allowing them to sign. Those options reduce your exposure to fraudulent signing, and the signed PDF returned to Salesforce includes the signature artefact.
Storage limits, file sizes and Notes & Attachments vs Files
Two numbers you must keep in mind when you review storage and backup controls:
- DocuGen accepts documents up to 40 MB when generating and bundling templates.
- Salesforce Notes & Attachments has a 25 MB single-file limit — Files is the correct destination for anything larger.
Recommendation: default templates that might exceed 25 MB (long contracts, image-heavy annexes, bundled templates) should be set to save in Files. That avoids failed uploads and ensures Files-based policies — like external file sync or encryption — apply.
Triggers, automation and the risk surface
Savvy DocuGen can run on a button click, a stage change, a field change, or when a new file arrives on a record. That flexibility is useful, but it expands the places you must control who can trigger generation:
- Button or manual runs: limit button visibility with page layout assignments and permission sets.
- Automated triggers (stage or field changes): review Flows and Process Builder entries that call DocuGen. Make sure only trusted system users or automation accounts can cause bulk generation.
- Incoming file triggers: validate the source and file type before a merge, to prevent malformed or oversized files entering an automated process.
Example scenario: if your Renewals team triggers 200 renewal pack generations per month on Opportunity stage change, ensure the automation user has restricted access and that Files storage quotas are monitored, otherwise you'll fill storage or create noisy access patterns.
Integration surface and what your security team actually needs to check
Key points your team will want on the checklist:
- No managed package to install — DocuGen connects through an authorised connection you approve. That means you do not install additional code into the org.
- Works in sandboxes exactly as in production, so you can run an end-to-end test of generation, signature, and file storage without touching production data (use test data and test Circularo accounts where possible).
- Signed PDFs are returned and stored in Salesforce, so audit trails and file retention are governed by your org's existing controls.
What to ask Circularo: confirm the signature session details and any ephemeral data retention they have during the signing process. DocuGen itself does not host the signature ceremony — it orchestrates it through your Circularo account and writes the result back into Salesforce.
If you need a short summary to hand to the security team: generated documents use your Salesforce storage, signed PDFs are written back to the originating record, the signature process runs under your Circularo account, and no managed package is installed. For files over 25 MB save to Files.
Savvy DocuGen fills Word and PDF templates from any Salesforce record, saves outputs to Files or Notes & Attachments per template, sends for signature through your Circularo account, and writes the signed PDF back into Salesforce. Try Savvy DocuGen in your sandbox to run a full end-to-end test with your security team.
Read next