Compliance engineered for the Cloud
Salesforce maintains a comprehensive set of compliance certifications and attestations to validate our #1 value of Trust.

External Security Assessments

Attestation of penetration tests and security assessments performed by third parties. The document does not contain details of any vulnerabilities or findings and is intended only to provide information on the tests performed and scope of testing. As verified by external audits, vulnerabilities discovered during testing are tracked and resolved in accordance with corporate policy and industry best practice.

Applicable documents by service

NameUpdated OnInfrastructureServices
Vulnerability/Penetration Report Summary - Engagement Web APIs (fka ExactTarget) 2025-02-10 First party Marketing Cloud
Vulnerability/Penetration Report Summary - Quip 2025-02-06 AWS LiveMessage, Sales Enablement, Quip and Salesforce.org Elevate
Vulnerability/Penetration Report Summary - B2C Mobify 2025-02-05 AWS B2C Commerce / Commerce Cloud
Vulnerability/Penetration Report Summary - Slack 2025-01-30 AWS Slack
Vulnerability/Penetration Report Summary - Salesforce Services 2025-01-28 First party, AWS, Hyperforce Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Heroku 2025-01-21 AWS Heroku
Vulnerability/Penetration Report Summary - Tableau Mobile (iOS/Android/Intune) 2024-12-10 AWS Tableau
Vulnerability/Penetration Report Summary - MuleSoft 2024-12-05 AWS MuleSoft
Vulnerability/Penetration Report Summary - OpenAI 2024-11-25 AWS Audience Studio and Data Studio
Customer Data Cloud
Einstein Platform
Heroku
LiveMessage, Sales Enablement, Quip and Salesforce.org Elevate
Marketing Cloud - Account Engagement
MuleSoft
MuleSoft Government Cloud
Salesforce Services, Sales Cloud, Service Cloud and Industries
Tableau
Vulnerability/Penetration Report Summary - Agentforce 2024-11-13 Hyperforce B2B Commerce
Customer Data Cloud
Einstein Platform
Marketing Cloud
Marketing Cloud - Account Engagement
MuleSoft
Salesforce Services, Sales Cloud, Service Cloud and Industries
Slack
Tableau
Vulnerability/Penetration Report Summary - RCG Industries 2024-09-24 First party, Hyperforce Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Tableau Cloud 2024-09-09 AWS Tableau
Vulnerability/Penetration Report Summary - Tableau Pulse 2024-09-09 AWS Tableau
Vulnerability/Penetration Report Summary - Spiff 2024-08-30 GCP Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - MC Intelligence (fka Datorama) 2024-08-27 AWS Marketing Cloud
Vulnerability/Penetration Report Summary - B2C Business Manager + OCAPI + SFRA 2024-08-01 First party, AWS B2C Commerce / Commerce Cloud
Vulnerability/Penetration Report Summary - Account Engagement (fka Pardot) 2024-07-29 AWS Marketing Cloud
Marketing Cloud - Account Engagement
Vulnerability/Penetration Report Summary - Salesforce Authenticator (Andr./iOS) 2024-07-25 First party Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Engagement (fka ExactTarget) 2024-07-23 First party Marketing Cloud
Vulnerability/Penetration Report Summary - Messaging (LiveMessage) 2024-07-12 AWS LiveMessage, Sales Enablement, Quip and Salesforce.org Elevate
Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Diffeo 2024-07-03 AWS Einstein Platform
Vulnerability/Penetration Report Summary - Sales Cloud Einstein Generative AI 2024-06-28 AWS, Hyperforce Einstein Platform
Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Tableau Bridge 2024-06-28 First party Tableau
Vulnerability/Penetration Report Summary - B2C Einstein, Reports and Dashboard 2024-06-24 First party B2C Commerce / Commerce Cloud
Vulnerability/Penetration Report Summary - Tableau Desktop Application 2024-06-24 First party Tableau
Vulnerability/Penetration Report Summary - Advertising Studio 2024-06-18 First party Marketing Cloud
Vulnerability/Penetration Report Summary - ClickSoftware FSE - WebApp & API 2024-06-13 AWS Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Vlocity Managed Packages 2024-06-03 First party Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Sales Cloud Einstein 2024-05-10 AWS Einstein Platform
Vulnerability/Penetration Report Summary - Service Cloud Einstein Generative AI 2024-05-01 AWS Einstein Platform
Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Tableau Server 2024-04-16 First party Tableau
Vulnerability/Penetration Report Summary - Social Studio 2024-04-15 First party Marketing Cloud
Vulnerability/Penetration Report Summary - Salesforce Maps Mobile (Andr./iOS) 2024-04-09 First party, AWS Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - AI for Marketing (fka MC Einstein) 2024-04-05 AWS Marketing Cloud
Vulnerability/Penetration Report Summary - Salesforce Maps 2024-03-22 First party, AWS Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Einstein Vision, Language & Voice 2024-01-30 AWS Einstein Platform
Vulnerability/Penetration Report Summary - Salesforce Mobile (Andr./iOS) 2024-01-25 First party Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Salesforce Inbox Mobile (Andr./iOS) 2024-01-08 First party Einstein Platform
Vulnerability/Penetration Report Summary - Salesforce Data Cloud (fka CDP) 2024-01-05 Hyperforce Customer Data Cloud
Vulnerability/Penetration Report Summary - Audience Studio (fka DMP, fka Krux) 2023-12-21 AWS Audience Studio and Data Studio
Marketing Cloud
Vulnerability/Penetration Report Summary - Marketing Cloud Mobile (Andr./iOS) 2023-12-14 First party Marketing Cloud
Vulnerability/Penetration Report Summary - Tableau CRM Mobile (Andr./iOS) 2023-12-05 First party Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary-Personalization fka Interaction Studio 2023-12-04 AWS, Hyperforce Marketing Cloud
Vulnerability/Penetration Report Summary - CRM Analytics (fka Tableau CRM) 2023-11-15 First party Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Mobile Shield (Andr./iOS) 2023-10-27 First party Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Tableau Prep 2023-10-25 AWS Tableau
Vulnerability/Penetration Report Summary - B2B Commerce Lightning (aka 1CB2B) 2023-10-05 First party B2B Commerce
Vulnerability/Penetration Report Summary - Service Cloud Einstein 2023-08-26 AWS Einstein Platform
Vulnerability/Penetration Report Summary - Field Service Lightning (Andr./iOS) 2022-12-07 First party Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Commerce Cloud Order Management + OCI 2022-11-08 First party B2C Commerce / Commerce Cloud
Vulnerability/Penetration Report Summary - B2B Commerce (CloudCraze) 2022-08-24 First party B2B Commerce
Vulnerability/Penetration Report Summary - myTrailhead 2022-08-16 AWS LiveMessage, Sales Enablement, Quip and Salesforce.org Elevate
Vulnerability/Penetration Report Summary - Tableau Cloud CMEK (Encryption) 2022-08-11 AWS Tableau
Vulnerability/Penetration Report Summary - Trailhead GO (Andr./iOS) 2022-07-26 AWS LiveMessage, Sales Enablement, Quip and Salesforce.org Elevate
Vulnerability/Penetration Report Summary - 1CB2C (One Commerce) 2022-07-12 First party B2C Commerce / Commerce Cloud
Vulnerability/Penetration Report Summary - Philanthropy Cloud Mobile (Andr./iOS) 2022-04-27 AWS LiveMessage, Sales Enablement, Quip and Salesforce.org Elevate
Vulnerability/Penetration Report Summary - ClickSoftware v8 - WebApp & API 2022-03-29 AWS Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - MacOS Tableau Desktop Application 2021-10-14 First party Tableau
Vulnerability/Penetration Report Summary - Salesforce Services Data Mask Add-on 2021-10-06 First party, AWS Salesforce Services, Sales Cloud, Service Cloud and Industries
Vulnerability/Penetration Report Summary - Omni Channel Inventory 2021-09-01 AWS, Hyperforce B2C Commerce / Commerce Cloud
Vulnerability/Penetration Report Summary - Salesforce.org Philanthropy Cloud 2021-01-21 AWS LiveMessage, Sales Enablement, Quip and Salesforce.org Elevate