Trust | Compliance

Compliance engineered for the Cloud

Salesforce maintains a comprehensive set of compliance certifications and attestations to validate our #1 value of Trust.

Services

Audience Studio and Data Studio

Audience Studio and Data Studio

Applicable to the services branded as Audience Studio and Data Studio (formerly branded as Krux). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

B2B Commerce

B2B Commerce

Applicable to the services branded as B2B Commerce (formerly branded as Cloud Craze). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

B2C Commerce / Commerce Cloud

B2C Commerce / Commerce Cloud

Applicable to the services branded as B2C Commerce/Commerce Cloud (formerly branded as Demandware). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

ClickSoftware

ClickSoftware

ClickSoftware enables companies to intelligently schedule and optimize field service work. Based on over 20 years of pioneering product development focused exclusively on optimizing field service, ClickSoftware provides automated context-based recommendations for service planning, execution, and analysis, connects service professionals to the business and customers using collaborative mobile tools and propels rapid value with intelligent decision making delivered to users in real-time.

Customer 360 Data Manager

Customer 360 Data Manager

Applicable to the services branded as Customer 360 Data Manager. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Data.com

Data.com

Applicable to the services branded as Data.com. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Desk.com

Desk.com

Applicable to the services branded as Desk.com. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Einstein Analytics

Einstein Analytics

Applicable to the services branded as Einstein Analytics (including Einstein Discovery provisioned after October 16, 2018). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Einstein Discovery Classic

Einstein Discovery Classic

Applicable to the services branded as Einstein Discovery Classic (formerly known as BeyondCore). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Einstein Platform

Einstein Platform

Applicable to the services and features branded as Sales Cloud Einstein, Pardot Einstein, Salesforce Inbox, Einstein Engagement Scoring, Einstein Vision and Language Services, Einstein Bots, Service Cloud Einstein, Einstein Prediction Builder, and the Einstein Activity Capture feature ("Covered Services"). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Government Cloud

Government Cloud

Applicable only to the environment branded and sold as Government Cloud. Salesforce Government Cloud is a partitioned instance of Salesforce’s industry-leading Platform-as-a-Service (PaaS) and Software-as-a-Service (SaaS), multi-tenant community cloud infrastructure specifically for use by U.S. federal, state, and local government customers, U.S. government contractors, and Federally Funded Research and Development Centers (FFRDCs). The Salesforce Government Cloud environment maintains the following U.S. Government authorizations: 1) Federal Risk and Authorization Management Program (FedRAMP) Moderate Authority to Operate (ATO) 2) Department of Defense (DoD) Impact Level 2 Provisional Authorization (PA) (based FedRAMP Moderate ATO) 3) Department of Defense (DoD) Impact Level 4 PA Additionally, the Salesforce Government Cloud has the following compliance certifications: SOC 1 & 2, PCI-DSS, ISO 27001, ISO 27017, ISO 27018, and HITRUST. Detailed compliance documentation related to the Salesforce Government Cloud’s U.S. Government authorizations may be obtained by U.S. Federal Government personnel via OMB MAX upon completing and submitting the Package Access Request Form available on the FedRAMP Marketplace (https://marketplace.fedramp.gov/#!/product/salesforce-government-cloud?sort=productName). Other organizations may request this documentation from their Salesforce account representative.

Government Cloud Plus

Government Cloud Plus

Applicable only to the environment branded and sold as Government Cloud Plus. Salesforce Government Cloud Plus is a partitioned instance of Salesforce’s industry-leading Platform-as-a-Service (PaaS) and Software-as-a-Service (SaaS), multi-tenant community cloud infrastructure specifically for use by U.S. federal, state, and local government customers, U.S. government contractors, and Federally Funded Research and Development Centers (FFRDCs). In May 2020, the Salesforce Government Cloud Plus environment has received the following U.S. Government authorizations: 1) Federal Risk and Authorization Management Program (FedRAMP) High Authority to Operate (ATO) 2) Department of Defense (DoD) Impact Level 2 Provisional Authorization (PA) (based FedRAMP High ATO) Additionally, the Salesforce Government Cloud Plus has the following compliance certifications: SOC 1 & 2, ISO 27001, ISO 27017, and ISO 27018. Detailed compliance documentation related to the Salesforce Government Cloud’s U.S. Government authorization may be obtained by U.S. Federal Government personnel via submitting the Package Access Request Form available on the FedRAMP Marketplace (https://marketplace.fedramp.gov/#!/product/salesforce-government-cloud-plus?sort=productName). Other organizations may request this documentation and other compliance certification documents relating to Government Cloud Plus from their Salesforce account representative.

Heroku

Heroku

Applicable to the services branded as Heroku. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

IoT Cloud

IoT Cloud

Applicable to the services branded as IoT Cloud. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Marketing Cloud

Marketing Cloud

Applicable to the services branded or sold as (collectively, 'Marketing Cloud'): Advertising Studio (including Advertising Audiences, Advertising Campaigns and Social.com), Datorama, ExactTarget (including Email Studio, Journey Builder and Mobile Studio), Interaction Studio, Predictive Intelligence (including Predictive Email, Predictive Web, Web & Mobile Analytics, and Web Personalization), and Social Studio. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Messaging and LiveMessage

Messaging and LiveMessage

Applicable to the services branded as Salesforce LiveMessage (formerly branded as Heywire) and Messaging, together the "Messaging Services". Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

MuleSoft

MuleSoft

Applicable to the services branded as MuleSoft or the Anypoint Platform ("MuleSoft Services"). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

MuleSoft Government Cloud

MuleSoft Government Cloud

The MuleSoft Government Cloud is a secure, FedRAMP-compliant deployment environment that enables U.S. Government agencies to use the Anypoint Platform in the cloud. The Mulesoft Government Cloud environment has been granted an agency-sponsored provisional Authority to Operate (ATO) of *Moderate* impact or below.

myTrailhead

myTrailhead

Applicable to the services branded as myTrailhead. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Pardot

Pardot

Applicable to the services branded as Pardot. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Quip

Quip

Applicable to the services branded as Quip. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Salesforce IQ

Salesforce IQ

Applicable to the services branded as SalesforceIQ CRM (“SalesforceIQ”). Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Salesforce Services

Salesforce Services

Applicable to the services branded as Sales Cloud, Service Cloud, Community Cloud, Chatter, Lightning Platform (including Force.com), IoT Explorer (including IoT Plus), Site.com, Database.com, Einstein Analytics (including Einstein Discovery), WDC, Messaging, Financial Services Cloud, Health Cloud, Sustainability Cloud, Consumer Goods Cloud, Manufacturing Cloud, Emergency Program Management, Salesforce CPQ and Salesforce Billing, Salesforce Maps, Salesforce Order Management, Workplace Command Center, Shift Management, and the Salesforce.org LLC ("Salesforce.org") services branded as Salesforce Advisor Link, foundationConnect (provisioned on or after August 19, 2019), Accounting Subledger, Salesforce.org Insights Platform: Data Integrity, and Nonprofit Cloud Case Management. Some specific certifications and reports may not apply to all services in the above list. Please refer to the "Audits and Certifications" section of the "Salesforce Security, Privacy and Architecture" document for any limitations — https://trust.salesforce.com/en/trust-and-compliance-documentation/

Tableau

Tableau

Tableau Software's (Tableau) products put the power of data into the hands of everyday people, allowing a broad population of business users to engage with their data, ask questions, solve problems, and create value. Based on innovative core technologies originally developed at Stanford University, Tableau's products reduce the complexity, inflexibility, and expense associated with traditional business intelligence applications.

Trailhead

Salesforce.com | Careers | Privacy Information

© Copyright 2020 Salesforce.com, inc. All rights reserved.