Compliance engineered for the Cloud
Salesforce maintains a comprehensive set of compliance certifications and attestations to validate our #1 value of Trust.

B2B Commerce

Applicable to the services branded as B2B Commerce (formerly branded as Cloud Craze).

Applicable documents by category

NameUpdated OnInfrastructureCategory
Salesforce Ransomware Mitigation Summary 2025-02-10 First party, AWS, Hyperforce FAQ's and White Papers
Salesforce Hyperforce Infrastructure - DR Summary 2025-02-07 Hyperforce Resilience, BCP & DR
ISO 9001:2015 - Salesforce, Inc. 2025-01-31 First party Other Reports and Certificates
Salesforce Data Cloud Security White Paper (JP) 2025-01-31 Hyperforce FAQ's and White Papers
Salesforce Hyperforce Infrastructure and Platform Security White Paper (JP) 2025-01-31 Hyperforce FAQ's and White Papers
Salesforce Enterprise Resilience/BCP Summary 2025-01-29 First party, AWS, Hyperforce Resilience, BCP & DR
Digital Operational Resilience Act (DORA) Frequently Asked Questions 2025-01-28 First party, AWS, Hyperforce Digital Operational Resilience Act (DORA)
Digital Operational Resilience Act (‘DORA’) Mapping 2025-01-28 First party, AWS, Hyperforce Digital Operational Resilience Act (DORA)
ISO Statement of Applicability (English) 2025-01-28 First party, AWS, Hyperforce ISO 27001
ISO Statement of Applicability (French) 2025-01-28 First party, AWS, Hyperforce ISO 27001
Salesforce Agentforce & Einstein Generative AI Security White Paper (EN) 2025-01-26 Hyperforce FAQ's and White Papers
PCI ASV Network Scan - Hyperforce EMEA (EU Central 2, Zurich, Switzerland 2025-01-21 Hyperforce PCI DSS
Spain ENS High - Corporate Services 2025-01-21 First party Spain Esquema Nacional de Seguridad (ENS)
Spain ENS High - Salesforce Services 2025-01-21 First party Spain Esquema Nacional de Seguridad (ENS)
Spain ENS High - Salesforce Services on Hyperforce 2025-01-21 Hyperforce Spain Esquema Nacional de Seguridad (ENS)
SOC 1 Bridge (Gap) Letter - Salesforce Services on Hyperforce 2025-01-06 Hyperforce SOC 1
Salesforce Third Party Risk Management Overview 2025-01-02 First party, AWS, Hyperforce FAQ's and White Papers
Vulnerability Management and Response Plan Summary 2025-01-02 First party, AWS, Hyperforce FAQ's and White Papers
HDS Certificate 2024-12-20 First party, AWS, Hyperforce Other Reports and Certificates
ISO/IEC 27001:2022 Certificate 2024-12-20 First party, AWS, Hyperforce ISO 27001
ISO/IEC 27017:2015 Certificate 2024-12-20 First party, AWS, Hyperforce ISO 27017
ISO/IEC 27018:2019 Certificate 2024-12-20 First party, AWS, Hyperforce ISO 27018
NEN 7510-1:2017 Certificate 2024-12-20 First party, AWS, Hyperforce NEN 7510
PCI Attestation of Compliance (AoC) - Salesforce Services on Hyperforce 2024-12-18 Hyperforce PCI DSS
PCI Responsibility Matrix - Salesforce Services on Hyperforce 2024-12-18 Hyperforce PCI DSS
SOC 1 Report - Salesforce Services 2024-12-17 First party, AWS SOC 1
SOC 1 Report - Salesforce Services on Hyperforce 2024-12-17 Hyperforce SOC 1
SOC 2 Report - Salesforce Services 2024-12-17 First party, AWS SOC 2
SOC 2 Report - Salesforce Services on Hyperforce 2024-12-17 Hyperforce SOC 2
SOC 3 Report - Salesforce Services on Hyperforce 2024-12-17 Hyperforce SOC 3
PCI ASV Network Scan - Hyperforce AMER (US West 2) N.California 2024-12-10 Hyperforce PCI DSS
SOC 1 Report - Corporate Services 2024-12-09 First party, AWS, Hyperforce SOC 1
SOC 2 Report - Corporate Services 2024-12-09 First party, AWS, Hyperforce SOC 2
Salesforce Secure Development Lifecycle Overview 2024-12-05 First party, AWS, Hyperforce FAQ's and White Papers
Salesforce Data Cloud Security White Paper (EN) 2024-11-30 Hyperforce FAQ's and White Papers
Salesforce Hyperforce Infrastructure and Platform Security White Paper (EN) 2024-11-30 Hyperforce FAQ's and White Papers
SOC 2 Report - OpenAI 2024-11-25 AWS, Hyperforce SOC 2
PCI ASV Network Scan - Core 2024-11-21 First party, AWS PCI DSS
PCI ASV Network Scan - Hyperforce EMEA (EU West 2) UK 2024-11-20 Hyperforce PCI DSS
[Whitepaper] Salesforce And The HIPAA Security Rule: Securing EPHI In The Cloud 2024-11-19 First party, AWS, Hyperforce HIPAA
Vulnerability/Penetration Report Summary - Agentforce 2024-11-13 Hyperforce External Security Assessments
PCI ASV Network Scan - Hyperforce APAC (North East 1) Tokyo, Japan 2024-10-29 Hyperforce PCI DSS
Salesforce Security (Incident) Response Plan 2024-09-05 First party, AWS, Hyperforce FAQ's and White Papers
GDPR - Data Protection Impact Assessments & Salesforce Services 2024-08-14 First party, AWS, Hyperforce GDPR
HITRUST Certificate - Salesforce Services on Hyperforce 2024-08-07 Hyperforce HITRUST
PCI Responsibility Matrix - Salesforce Services 2024-07-31 First party, AWS PCI DSS
UK Cyber Essentials Plus Certificate 2024-07-24 First party, AWS, Hyperforce Other Reports and Certificates
PCI Attestation of Compliance (AoC) - Salesforce Services 2024-07-16 First party, AWS PCI DSS
PCI ASV Network Scan - Hyperforce AMER (US East 1) N.Virginia 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce AMER (US East 2) Ohio 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce APAC (North East 2) Seoul, South Korea 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce APAC (South 1) Mumbai, India 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce APAC (South East 1) Singapore) 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce APAC (South East 2) Sydney, Australia 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce APAC (South East 3) Indonesia 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce Canada (CA Central 1) Canada 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce EMEA (EU Central 1) Germany 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce EMEA (EU North 1) Sweden 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce EMEA (EU West 3) France 2024-07-12 Hyperforce PCI DSS
PCI ASV Network Scan - Hyperforce LACA (SA East 1) Brazil 2024-07-12 Hyperforce PCI DSS
Salesforce EU Processor Binding Corporate Rules 2024-07-01 First party, AWS, Hyperforce Salesforce BCRs
Salesforce UK Processor Binding Corporate Rules 2024-07-01 First party, AWS, Hyperforce Salesforce BCRs
Salesforce Health & Safety Policy 2024-06-26 First party, AWS, Hyperforce, Azure, GCP Resilience, BCP & DR
DR Summary and Testing - Salesforce Services on Hyperforce 2024-04-26 Hyperforce Resilience, BCP & DR
Vulnerability/Penetration Report Summary - B2B Commerce Lightning (aka 1CB2B) 2023-10-05 First party External Security Assessments
Einstein GPT Security White Paper (JP) 2023-09-29 Hyperforce FAQ's and White Papers
Security Perspective on the Shared Responsibility Model 2023-07-24 First party, AWS, Hyperforce FAQ's and White Papers
Data Privacy Framework (DPF) Registration 2023-07-17 First party, AWS, Hyperforce U.S. Data Privacy Framework (DPF)
Salesforce Vulnerability Management Program Overview 2022-12-12 First party, AWS, Hyperforce FAQ's and White Papers
Salesforce Enterprise Security Overview (JP) 2022-10-04 First party, AWS, Hyperforce FAQ's and White Papers
Salesforce Security (Incident) Response Plan (JP) 2022-10-04 First party, AWS, Hyperforce FAQ's and White Papers
Vulnerability/Penetration Report Summary - B2B Commerce (CloudCraze) 2022-08-24 First party External Security Assessments
Security Perspective on the Shared Responsibility Model (JP) 2022-08-02 First party, AWS, Hyperforce FAQ's and White Papers
Salesforce Enterprise Security Overview 2022-03-11 First party, AWS, Hyperforce FAQ's and White Papers
International Transfers of EU Personal Data to Salesforce's Services FAQ 2020-07-16 First party, AWS, Hyperforce U.S. Data Privacy Framework (DPF)
APEC Processor Seal - Salesforce 2020-07-10 First party, Hyperforce APEC Certification for Processors and Controllers