Compliance engineered for the Cloud
Salesforce maintains a comprehensive set of compliance certifications and attestations to validate our #1 value of Trust.

Heroku

Applicable to the services branded as Heroku.

Applicable documents by category

NameUpdated OnInfrastructureCategory
Salesforce Enterprise Resilience/BCP Summary 2025-01-29 First party, AWS, Hyperforce Resilience, BCP & DR
Digital Operational Resilience Act (DORA) Frequently Asked Questions 2025-01-28 First party, AWS, Hyperforce Digital Operational Resilience Act (DORA)
Digital Operational Resilience Act (‘DORA’) Mapping 2025-01-28 First party, AWS, Hyperforce Digital Operational Resilience Act (DORA)
ISO Statement of Applicability (English) 2025-01-28 First party, AWS, Hyperforce ISO 27001
ISO Statement of Applicability (French) 2025-01-28 First party, AWS, Hyperforce ISO 27001
Spain ENS High - Corporate Services 2025-01-21 First party Spain Esquema Nacional de Seguridad (ENS)
Vulnerability/Penetration Report Summary - Heroku 2025-01-21 AWS External Security Assessments
SOC 2 Report - Amazon Web Services (AWS) 2025-01-10 AWS, Hyperforce SOC 2
SOC 1 Bridge (Gap) Letter - Heroku 2025-01-06 AWS SOC 1
Salesforce Third Party Risk Management Overview 2025-01-02 First party, AWS, Hyperforce FAQ's and White Papers
Vulnerability Management and Response Plan Summary 2025-01-02 First party, AWS, Hyperforce FAQ's and White Papers
HDS Certificate 2024-12-20 First party, AWS, Hyperforce HDS
ISO/IEC 27001:2022 Certificate 2024-12-20 First party, AWS, Hyperforce ISO 27001
ISO/IEC 27017:2015 Certificate 2024-12-20 First party, AWS, Hyperforce ISO 27017
ISO/IEC 27018:2019 Certificate 2024-12-20 First party, AWS, Hyperforce ISO 27018
NEN 7510-1:2017 Certificate 2024-12-20 First party, AWS, Hyperforce NEN 7510
SOC 1 Report - Heroku 2024-12-19 AWS SOC 1
SOC 2 Report - Heroku 2024-12-19 AWS SOC 2
SOC 3 Report - Heroku 2024-12-19 AWS SOC 3
SOC 1 Report - Amazon Web Services (AWS) 2024-12-13 AWS, Hyperforce SOC 1
SOC 1 Report - Corporate Services 2024-12-09 First party, AWS, Hyperforce SOC 1
SOC 2 Report - Corporate Services 2024-12-09 First party, AWS, Hyperforce SOC 2
Salesforce Secure Development Lifecycle Overview 2024-12-05 First party, AWS, Hyperforce FAQ's and White Papers
SOC 2 Report - OpenAI 2024-11-25 AWS, Hyperforce SOC 2
Vulnerability/Penetration Report Summary - OpenAI 2024-11-25 AWS External Security Assessments
[Whitepaper] Salesforce And The HIPAA Security Rule: Securing EPHI In The Cloud 2024-11-19 First party, AWS, Hyperforce HIPAA
Salesforce Security (Incident) Response Plan 2024-09-05 First party, AWS, Hyperforce FAQ's and White Papers
GDPR - Data Protection Impact Assessments & Salesforce Services 2024-08-14 First party, AWS, Hyperforce GDPR
DR/BCP Summary - Heroku Services 2024-07-31 AWS Resilience, BCP & DR
PCI Attestation of Compliance (AoC) - Heroku 2024-07-26 AWS PCI DSS
PCI Responsibility Matrix - Heroku 2024-07-26 AWS PCI DSS
UK Cyber Essentials Plus Certificate 2024-07-24 First party, AWS, Hyperforce UK Cyber Essentials Plus
Salesforce EU Processor Binding Corporate Rules 2024-07-01 First party, AWS, Hyperforce Salesforce BCRs
Salesforce UK Processor Binding Corporate Rules 2024-07-01 First party, AWS, Hyperforce Salesforce BCRs
Salesforce Health & Safety Policy 2024-06-26 First party, AWS, Hyperforce, Azure, GCP Resilience, BCP & DR
TX-RAMP - Heroku 2024-06-20 AWS TX-RAMP
PCI ASV Network Scan - Heroku 2023-09-08 AWS PCI DSS
Data Privacy Framework (DPF) Registration 2023-07-17 First party, AWS, Hyperforce U.S. Data Privacy Framework (DPF)
ISMAP Cloud Service List - Heroku 2023-06-16 AWS ISMAP
Salesforce Vulnerability Management Program Overview 2022-12-12 First party, AWS, Hyperforce FAQ's and White Papers
Salesforce Security (Incident) Response Plan (JP) 2022-10-04 First party, AWS, Hyperforce FAQ's and White Papers
CSA CAIQ - Heroku 2022-02-03 AWS CSA STAR
International Transfers of EU Personal Data to Salesforce's Services FAQ 2020-07-16 First party, AWS, Hyperforce U.S. Data Privacy Framework (DPF)
APEC Processor Seal - Salesforce 2020-07-10 First party, Hyperforce APEC Certification for Processors and Controllers