Our Unified Security Framework
Foundationals, Configurables, and Enhanceables
Our commitment to securing and protecting your data comes to life by delivering innovative solutions, expert guidance, and reliable access to data and systems to our customers.
Trust is Our #1 Value
At Salesforce, trust isn’t a feature – it’s our highest value. Every product decision, every line of code, and every compliance certificate starts with a single question: does this keep our customers safe?
When you use Salesforce, you’re not just getting a CRM – you’re getting a platform built from the ground up with security embedded into every decision we make.
Protecting Data is a Partnership
Salesforce operates using a shared responsibility model. We provide the foundational security built into our platform and infrastructure, while you ensure that the security controls within Salesforce are configured correctly.
Salesforce’s Responsibility
- Build innovative and secure solutions
- Prepare customers for evolving threats
- Deliver reliable access to systems
- Meet compliance standards for customers
Customers’ Responsibility
- Implement security controls
- Control user permissions and access
- Configure settings using security best practices
- Ensure data integrity and resilience
Our Security Framework
Each layer is a visual card – click to expand and explore product capabilities, Salesforce security features, and solutions for meeting your regulatory and policy obligations.
Foundationals — Layer 01 of 03
The Foundation of Trust
Built-in always-on protections Salesforce builds and maintains on every customer's behalf. Always working in the background — no setup needed.
Secure Development
SDL practices baked into every release: threat modeling, security reviews, and scanning on all platform code.
Hyperforce
Next-gen public cloud infrastructure with built-in compliance, agility, and data residency controls.
Encryption
All data encrypted at rest and TLS 1.2+ in transit. Fully automatic platform-wide. No keys to manage.
Host, Storage & Network Security
Global data centers with biometric access, 24/7 security, network segmentation, DDoS defense and redundancy.
Third Party Auditing & Testing
Scheduled pen testing, continuous vulnerability scanning, and an independent bug bounty program.
Least Privilege Access
Internal access to customer data is least-privilege, need-based, time-limited, logged, and regularly reviewed.
Site Reliability & Disaster Recovery
Multi-region redundancy, automated failover, and 99.9%+ uptime SLAs with rapid recovery.
24/7 Global Monitoring
Continuous threat and incident monitoring by a global team with real-time alerting and response.
Compliance & Certifications
SOC 2 Type II, ISO, PCI DSS L1, HIPAA-eligible, FedRAMP Authorized, and Japan CS Gold.
Government Cloud
FedRAMP-authorized Government Cloud for public sector, meeting FISMA, ITAR, and DoD IL2/4 requirements.
Configurables – Layer 02 of 03
Managing Your Security Settings
Built-in controls your admins configure to meet security requirements and best practices. Available to all Salesforce customers – but require deliberate setup by you.
Multi-Factor Authentication
Enforce MFA for all users via Salesforce Authenticator, TOTP apps, or hardware security keys.
IP Restrictions
Restrict IP ranges for profiles to ensure only trusted users can access Salesforce.
User Access Controls
Limit access at the object, field, and record level via profiles, roles, and permission sets.
Auditing
Built-in audit capabilities including Setup Audit Trail, Login History, and Field History Tracking. Review configuration changes, login activity, and data modifications to detect unauthorized actions.
Health Check
Security Health Check scores your org against a baseline and flags gaps with remediation guidance.
Permission Sets
Granular permission sets extend access without changing profiles, and groups for role-based access at scale.
Login History Reports
Track logins, failures, source IPs, and browser types to identify anomalous patterns and suspicious access.
Single Sign-On (SSO)
Integrate with Okta, Azure AD, Ping, or any SAML 2.0/OAuth 2.0 provider to unify identities into one profile.
Enhanceables – Layer 03 of 03
Advanced Controls
Part of Salesforce Guardian, these premium add-ons are built for organizations navigating strict regulations or sophisticated threats. They are available individually or as a complete bundle.
Salesforce Shield
Flagship security suite combining Event Monitoring, Platform Encryption, Audit Trail, and Data Detect in one bundle.
Shield: Platform Encryption
Secure data at the field and database levels with AES-256 encryption and flexible key management options.
Shield: Event Monitoring
Track 90+ event types and use custom policies to automatically block risky user actions in real time.
Shield: Field Audit Trail
Audit who, what, and when data changes. Retain log of field history changes to comply with regulations.
Shield: Data Detect
Automatically discover sensitive data across your org. Use scan results to apply additional security controls.
Security Center
Centrally manage security health, identify misconfigurations, and investigate threats with Agentforce.
Privacy Center
Streamline data privacy, manage consent policies, and ensure GDPR and CCPA compliance with Agentforce.
Data Mask & Seed
Anonymize sensitive production data and seed test environments with safe data to accelerate development.
Backup & Recover
Automate daily backups of Salesforce data and metadata, get proactive alerts, and easily restore data.
Archive
Relocate historical records via automated policies to boost performance while maintaining data access.
Match Your Security Needs to the Right Solutions
Your security strategy should be driven by your specific business challenges. The following use cases illustrate how Salesforce Guardian can help you address sophisticated risks, protect sensitive data, and maintain compliance.
| Your Situation | Recommended Focus | Layer |
|---|---|---|
| You’re in a regulated industry (healthcare, finance, gov) |
Meet strict healthcare, financial, and public sector regulations with our Salesforce Guardian portfolio. Read the Regulations Whitepaper to match our products to your specific compliance needs. | Enhanceables |
| You need to enforce company access policies |
Configure MFA, SSO & Customer Identity, profiles, roles, and session settings to match your IT policy | Configurables |
| You need to protect sandbox and dev environments |
Use Data Mask & Seed to anonymize production data for dev/test, preventing sensitive data exposure during development | Enhanceables |
| You need data residency in a specific country |
Deploy on Hyperforce to pin your data to a specific region; add Hyperforce Operating Zone for in-region EU support | Enhanceables |
| You want to increase visibility, detect insider threats or unusual behavior |
Enable Shield Event Monitoring for 90+ event types and custom blocking policies; add Security Center for org-wide visibility | Enhanceables |
| You need to manage data privacy & compliance (GDPR/CCPA) |
Deploy Privacy Center for consent management, right-to-be-forgotten automation, and data retention governance | Enhanceables |
| You need to protect against data loss or corruption |
Implement Backup & Recover for automated daily backups, proactive alerts, and point-in-time restore | Enhanceables |
A note on the Enhanceables
Our add-on security and privacy products – collectively called Salesforce Guardian – can be purchased on top of your core license. Here’s a glimpse into what our products do.
Ready to take your security to the next level?
Take the next step to explore our solutions, learn security best practices, or connect with our team.