SECURITY STANDARDS

Salesforce Security Standards

How we protect customer data, secure access, and maintain trusted Salesforce environments.

Salesforce security is managed through platform controls, internal policies, continuous monitoring, and user accountability. This page outlines the standards we maintain across access management, data protection, configuration governance, and compliance readiness.

OUR COMMITMENT

Security Is Central to How We Operate

We treat Salesforce security as a continuous practice — not a one-time configuration. Our commitment covers the full lifecycle of data, access, and platform governance.

Protect Customer & Business Data

Customer, employee, and business data is protected through platform controls, access restrictions, and data governance policies.

Least-Privilege Access

Users are granted only the access required for their specific job responsibilities — no more, no less.

Secure Configuration Standards

Salesforce environments are configured to meet security baselines and reviewed using the Salesforce Health Check.

Continuous Monitoring

Login activity, configuration changes, and user behavior are monitored on an ongoing basis to detect unusual patterns.

Regular Access Reviews

User access, profiles, and permission sets are reviewed on a recurring basis to ensure alignment with current roles.

Compliance & Audit Readiness

Our Salesforce security program supports alignment with common compliance frameworks and internal audit requirements.

IDENTITY & ACCESS

Identity and Access Management

We use role-based access controls to ensure users only have access to the Salesforce data and functionality required for their job responsibilities.

Access is granted through a structured provisioning process, reviewed regularly, and revoked promptly when no longer required.

Access Governance Principles

Least-privilege by default

Documented provisioning and deprovisioning

Separation of duties for admins and approvers

Regular access recertification

Single Sign-On (SSO) integration where applicable

Multi-Factor Authentication (MFA) enforced for all users

Strong password policies aligned with organizational standards

Role-based access control with defined role hierarchy

Profile, permission set, and permission set group governance

Login IP ranges and trusted network policies

Session timeout standards enforced at the org level

User provisioning process tied to HR or identity management workflows

Timely deactivation of departed or role-changed users

DATA PROTECTION

Data Protection Standards

Salesforce data is protected at every layer — from who can see individual fields, to how records are shared, to how data is exported and retained.

Field-Level Security

Sensitive fields are restricted to authorized user profiles and permission sets only.

Object-Level Permissions

Object access (read, create, edit, delete) is controlled through profiles and permission sets.

Record-Level Sharing

Sharing rules and manual sharing govern which users can access specific records beyond their default access.

Org-Wide Defaults

Organization-wide default settings establish the baseline access level for each object across the org.

Data Classification

Data is classified by sensitivity and handled according to appropriate controls and access restrictions.

Encryption Standards

Salesforce Shield Platform Encryption is used where applicable to protect data at rest for sensitive fields.

Export & Report Controls

Report and data export access is limited to authorized users, and bulk export activity is monitored.

Retention & Deletion

Data retention and deletion policies are documented and implemented to meet business and regulatory requirements.

CHANGE GOVERNANCE

Salesforce Configuration Governance

All Salesforce configuration and code changes follow a structured change management process to prevent unauthorized or untested changes from reaching the production environment.

Changes are developed and tested in sandbox environments, reviewed for security and functional impact, approved by appropriate stakeholders, and documented before deployment.

Formal change management process for all Salesforce modifications

Sandbox environments used for all development and testing

Deployment approvals required before production release

Change sets, Salesforce CLI, or DevOps tools used for controlled deployments

Configuration and code review prior to production release

Documentation standards maintained for all significant changes

Separation of duties between developers, admins, and approvers

Post-deployment validation and rollback procedures

MONITORING & AUDITING

Monitoring, Logging, and Auditing

We regularly review Salesforce logs and audit records to identify unauthorized access attempts, configuration changes, and unusual user activity.

Login History Reviews

Login history is reviewed regularly to identify failed attempts, unusual access times, or unexpected IP addresses.

Setup Audit Trail

All configuration changes in Salesforce are logged in the Setup Audit Trail and reviewed on a recurring basis.

Field History Tracking

Field History Tracking is enabled on critical objects and fields to maintain a tamper-evident record of data changes.

Suspicious Activity Alerts

Alerts are configured for unusual login behavior, including logins from new locations, devices, or outside business hours.

Event Monitoring

Salesforce Event Monitoring (where applicable) provides visibility into report exports, API calls, and user behavior.

Periodic Audit Reviews

Access, permissions, and configuration audits are conducted on a defined cadence to confirm continued alignment with security standards.

INTEGRATIONS & APPS

Third-Party App and Integration Security

All third-party applications, integrations, and API connections are reviewed and approved before being granted access to Salesforce data or functionality.

Integration users are provisioned with the minimum access required, and all external connections are reviewed on a recurring basis.

AppExchange app security review prior to installation

Connected app approval standards enforced at the org level

API access controls with scope limitations

OAuth scope review for all connected applications

Named Credentials used for secure callout authentication

Integration user governance with least-privilege access

Vendor security review for significant third-party integrations

Periodic review of all installed packages and external connections

USER RESPONSIBILITIES

User Security Responsibilities

Every Salesforce user plays a role in maintaining a secure environment. The following standards apply to all users with access to Salesforce.

Protect Credentials

Never share login credentials. Passwords must meet organizational complexity requirements and be kept confidential.

Use MFA

Multi-Factor Authentication is required for all Salesforce access. Users must not attempt to bypass MFA requirements.

Limit Data Exports

Sensitive data should not be exported from Salesforce unless there is a documented business need and appropriate authorization.

Report Suspicious Activity

Users who observe unusual behavior, unauthorized access, or potential security issues must report them immediately.

Follow Data Policies

All users are expected to follow internal data handling, classification, and retention policies.

Complete Security Training

Required security awareness and Salesforce-specific training must be completed as assigned.

Use Approved Tools Only

Only tools, integrations, and applications that have been reviewed and approved may be connected to Salesforce.

Escalate Promptly

Security concerns should be escalated immediately — not deferred or resolved informally.

INCIDENT RESPONSE

Incident Response

Potential Salesforce security incidents are handled through a defined process designed to contain the issue, protect data, and prevent recurrence.

01

Report the Concern

Users report suspected security issues to the internal security or Salesforce administration team through the designated reporting channel.

02

Internal Escalation

Reports are immediately escalated to appropriate security and IT stakeholders for triage and initial assessment.

03

Investigation & Containment

The scope of the incident is assessed, affected access or functionality is contained, and evidence is preserved for review.

04

Access Suspension

User accounts, connected apps, or integration credentials are suspended where necessary to prevent further exposure.

05

Root Cause Analysis

After containment, a root cause analysis is completed to understand how the incident occurred and what controls failed.

06

Remediation & Notification

Identified gaps are remediated, controls are strengthened, and customers or stakeholders are notified where applicable.

COMPLIANCE ALIGNMENT

Compliance and Regulatory Alignment

Our Salesforce security program supports alignment with common compliance and regulatory frameworks. The controls described on this page help support audit readiness across the following standards.

Note: References to specific frameworks indicate that our security practices support alignment with those standards — not that the organization is formally certified unless otherwise specified.

SOC 2

Supports alignment with Trust Services Criteria for security, availability, and confidentiality.

ISO 27001

Supports alignment with information security management system controls.

GDPR

Supports data subject rights, access controls, and data protection obligations.

HIPAA

Supports safeguards for protected health information where applicable.

CCPA / CPRA

Supports California consumer privacy rights and data handling obligations.

Internal Audit

Supports internal audit requirements and documentation standards.

REVIEW CADENCE

Security Review Cadence

Security controls are not a one-time configuration — they require ongoing review, testing, and updating to remain effective as the business, team, and threat landscape evolve.

We maintain a defined review schedule across access, permissions, integrations, and policies to ensure our Salesforce security posture stays current.

Quarterly

User access reviews and permission audits

Quarterly

Review of connected apps and third-party integrations

Semi-Annual

Salesforce Health Check review and remediation

Annual

Security policy and standards review and update

Ongoing

Monitoring of Salesforce release notes and security advisories

As Needed

Penetration testing or vulnerability assessments

As Needed

Post-incident security reviews and control updates

PLATFORM FEATURES

Salesforce Platform Security Features We Use

The following Salesforce platform features are used as part of our security program.

Multi-Factor Authentication (MFA)
Role Hierarchy
Profiles and Permission Sets
Permission Set Groups
Field-Level Security
Sharing Rules
Organization-Wide Defaults
Login IP Restrictions
Session Timeout Settings
Setup Audit Trail
Field History Tracking
Login History Reviews
Salesforce Health Check
Named Credentials
Connected App Controls
Transaction Security Policies
Salesforce Shield (Platform Encryption)
Event Monitoring
SECURITY CONTACT

Report a Salesforce Security Concern

If you believe you have identified a Salesforce security issue or need to request access changes, please contact our internal security or Salesforce administration team.

Privacy PolicyContact UsAbout Cloud Nexus

Last updated: June 2026