FinDock builds payment infrastructure for nonprofits and financial services, operating as a 100% native Salesforce app since 2014. The company processes recurring donations and payment flows directly within the Salesforce platform, which means every transaction touches CRM data, donor records, and conversational context. That's the surface area: payment processing layered into Salesforce integration, where sensitive financial data meets donor PII inside a multi-tenant cloud environment.
The threat model here is concrete. You're defending payment data in transit and at rest across Salesforce's ecosystem, protecting donor financial information, and ensuring PCI compliance for recurring transaction flows. Nonprofits are targeted for their often-thin security budgets; the attack surface includes credential stuffing against donor portals, API abuse on payment endpoints, and supply-chain risk through Salesforce third-party integrations. The platform handles real money moving through real organizations - ABN AMRO is among their clients - so the stakes are not abstract.
Engineering operates in cross-functional product teams alongside craft-based guilds called Nexi, where engineers deepen their technical discipline while shipping production systems. The company holds Great Place to Work certification for four consecutive years, with a culture centered on ownership and trust. For security professionals, the draw is straightforward: hardening payment infrastructure inside one of the most complex enterprise platforms, where Salesforce-native architecture means working with Apex, platform events, and managed package security models at scale.






