Salesforce Security Standards
How we protect customer data, secure access, and maintain trusted Salesforce environments.
Salesforce security is managed through platform controls, internal policies, continuous monitoring, and user accountability. This page outlines the standards we maintain across access management, data protection, configuration governance, and compliance readiness.
Security Is Central to How We Operate
We treat Salesforce security as a continuous practice — not a one-time configuration. Our commitment covers the full lifecycle of data, access, and platform governance.
Protect Customer & Business Data
Customer, employee, and business data is protected through platform controls, access restrictions, and data governance policies.
Least-Privilege Access
Users are granted only the access required for their specific job responsibilities — no more, no less.
Secure Configuration Standards
Salesforce environments are configured to meet security baselines and reviewed using the Salesforce Health Check.
Continuous Monitoring
Login activity, configuration changes, and user behavior are monitored on an ongoing basis to detect unusual patterns.
Regular Access Reviews
User access, profiles, and permission sets are reviewed on a recurring basis to ensure alignment with current roles.
Compliance & Audit Readiness
Our Salesforce security program supports alignment with common compliance frameworks and internal audit requirements.
Identity and Access Management
We use role-based access controls to ensure users only have access to the Salesforce data and functionality required for their job responsibilities.
Access is granted through a structured provisioning process, reviewed regularly, and revoked promptly when no longer required.
Access Governance Principles
Least-privilege by default
Documented provisioning and deprovisioning
Separation of duties for admins and approvers
Regular access recertification
Single Sign-On (SSO) integration where applicable
Multi-Factor Authentication (MFA) enforced for all users
Strong password policies aligned with organizational standards
Role-based access control with defined role hierarchy
Profile, permission set, and permission set group governance
Login IP ranges and trusted network policies
Session timeout standards enforced at the org level
User provisioning process tied to HR or identity management workflows
Timely deactivation of departed or role-changed users
Data Protection Standards
Salesforce data is protected at every layer — from who can see individual fields, to how records are shared, to how data is exported and retained.
Field-Level Security
Sensitive fields are restricted to authorized user profiles and permission sets only.
Object-Level Permissions
Object access (read, create, edit, delete) is controlled through profiles and permission sets.
Record-Level Sharing
Sharing rules and manual sharing govern which users can access specific records beyond their default access.
Org-Wide Defaults
Organization-wide default settings establish the baseline access level for each object across the org.
Data Classification
Data is classified by sensitivity and handled according to appropriate controls and access restrictions.
Encryption Standards
Salesforce Shield Platform Encryption is used where applicable to protect data at rest for sensitive fields.
Export & Report Controls
Report and data export access is limited to authorized users, and bulk export activity is monitored.
Retention & Deletion
Data retention and deletion policies are documented and implemented to meet business and regulatory requirements.
Salesforce Configuration Governance
All Salesforce configuration and code changes follow a structured change management process to prevent unauthorized or untested changes from reaching the production environment.
Changes are developed and tested in sandbox environments, reviewed for security and functional impact, approved by appropriate stakeholders, and documented before deployment.
Formal change management process for all Salesforce modifications
Sandbox environments used for all development and testing
Deployment approvals required before production release
Change sets, Salesforce CLI, or DevOps tools used for controlled deployments
Configuration and code review prior to production release
Documentation standards maintained for all significant changes
Separation of duties between developers, admins, and approvers
Post-deployment validation and rollback procedures
Monitoring, Logging, and Auditing
We regularly review Salesforce logs and audit records to identify unauthorized access attempts, configuration changes, and unusual user activity.
Login History Reviews
Login history is reviewed regularly to identify failed attempts, unusual access times, or unexpected IP addresses.
Setup Audit Trail
All configuration changes in Salesforce are logged in the Setup Audit Trail and reviewed on a recurring basis.
Field History Tracking
Field History Tracking is enabled on critical objects and fields to maintain a tamper-evident record of data changes.
Suspicious Activity Alerts
Alerts are configured for unusual login behavior, including logins from new locations, devices, or outside business hours.
Event Monitoring
Salesforce Event Monitoring (where applicable) provides visibility into report exports, API calls, and user behavior.
Periodic Audit Reviews
Access, permissions, and configuration audits are conducted on a defined cadence to confirm continued alignment with security standards.
Third-Party App and Integration Security
All third-party applications, integrations, and API connections are reviewed and approved before being granted access to Salesforce data or functionality.
Integration users are provisioned with the minimum access required, and all external connections are reviewed on a recurring basis.
AppExchange app security review prior to installation
Connected app approval standards enforced at the org level
API access controls with scope limitations
OAuth scope review for all connected applications
Named Credentials used for secure callout authentication
Integration user governance with least-privilege access
Vendor security review for significant third-party integrations
Periodic review of all installed packages and external connections
User Security Responsibilities
Every Salesforce user plays a role in maintaining a secure environment. The following standards apply to all users with access to Salesforce.
Protect Credentials
Never share login credentials. Passwords must meet organizational complexity requirements and be kept confidential.
Use MFA
Multi-Factor Authentication is required for all Salesforce access. Users must not attempt to bypass MFA requirements.
Limit Data Exports
Sensitive data should not be exported from Salesforce unless there is a documented business need and appropriate authorization.
Report Suspicious Activity
Users who observe unusual behavior, unauthorized access, or potential security issues must report them immediately.
Follow Data Policies
All users are expected to follow internal data handling, classification, and retention policies.
Complete Security Training
Required security awareness and Salesforce-specific training must be completed as assigned.
Use Approved Tools Only
Only tools, integrations, and applications that have been reviewed and approved may be connected to Salesforce.
Escalate Promptly
Security concerns should be escalated immediately — not deferred or resolved informally.
Incident Response
Potential Salesforce security incidents are handled through a defined process designed to contain the issue, protect data, and prevent recurrence.
Report the Concern
Users report suspected security issues to the internal security or Salesforce administration team through the designated reporting channel.
Internal Escalation
Reports are immediately escalated to appropriate security and IT stakeholders for triage and initial assessment.
Investigation & Containment
The scope of the incident is assessed, affected access or functionality is contained, and evidence is preserved for review.
Access Suspension
User accounts, connected apps, or integration credentials are suspended where necessary to prevent further exposure.
Root Cause Analysis
After containment, a root cause analysis is completed to understand how the incident occurred and what controls failed.
Remediation & Notification
Identified gaps are remediated, controls are strengthened, and customers or stakeholders are notified where applicable.
Compliance and Regulatory Alignment
Our Salesforce security program supports alignment with common compliance and regulatory frameworks. The controls described on this page help support audit readiness across the following standards.
Note: References to specific frameworks indicate that our security practices support alignment with those standards — not that the organization is formally certified unless otherwise specified.
SOC 2
Supports alignment with Trust Services Criteria for security, availability, and confidentiality.
ISO 27001
Supports alignment with information security management system controls.
GDPR
Supports data subject rights, access controls, and data protection obligations.
HIPAA
Supports safeguards for protected health information where applicable.
CCPA / CPRA
Supports California consumer privacy rights and data handling obligations.
Internal Audit
Supports internal audit requirements and documentation standards.
Security Review Cadence
Security controls are not a one-time configuration — they require ongoing review, testing, and updating to remain effective as the business, team, and threat landscape evolve.
We maintain a defined review schedule across access, permissions, integrations, and policies to ensure our Salesforce security posture stays current.
User access reviews and permission audits
Review of connected apps and third-party integrations
Salesforce Health Check review and remediation
Security policy and standards review and update
Monitoring of Salesforce release notes and security advisories
Penetration testing or vulnerability assessments
Post-incident security reviews and control updates
Salesforce Platform Security Features We Use
The following Salesforce platform features are used as part of our security program.
Report a Salesforce Security Concern
If you believe you have identified a Salesforce security issue or need to request access changes, please contact our internal security or Salesforce administration team.
Last updated: June 2026
