Q39
Are you PCI DSS compliant? At what level?
Salesforce is PCI DSS Level 1 certified service provider, meeting the most rigorous security standards for handling payment card data.
ThirdProof independently checks public intelligence sources to show what your team can verify about Salesforce before Salesforce sends a questionnaire or a security document.
Salesforce's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Salesforce — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Salesforce's own trust page.
✓ FedRAMP Certified — Class D (High) Checked August 2026.
Salesforce Government Cloud Plus is FedRAMP Certified at Class D (High) via the JAB path (package FR2003061248). Commercial Salesforce orgs are not covered by this certification.
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 25 returning usable evidence. The Salesforce assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Salesforce Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 59% of a 133-question vendor security questionnaire — without waiting for Salesforce. The remaining 54 are listed as open, so the follow-up you send is short and specific.
Q39
Salesforce is PCI DSS Level 1 certified service provider, meeting the most rigorous security standards for handling payment card data.
Q37
SOC 2 Type II: Vendor attested — trust page
Q42
Salesforce is GDPR compliant and provides a Data Processing Agreement (DPA) including European Commission Standard Contractual Clauses, authorized sub-processor list, and technical descriptions.
Q40
Salesforce can be used in a HIPAA-compliant manner and provides a Business Associate Agreement (BAA) with specific restrictions and covered services listed at https://www.salesforce.com/company/legal/business-associate-addendum-restrictions.
Q23
Salesforce Shield Platform Encryption uses Advanced Encryption Standard (AES) with 256-bit encryption for data at rest using strong, probabilistic encryption.
+ 74 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Salesforce for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Salesforce
Salesforce is a mature, enterprise-scale SaaS vendor offering customer relationship management (CRM) and related cloud services.
The vendor demonstrates strong positive signals across compliance, infrastructure, and security governance. Salesforce holds FedRAMP authorization at Moderate impact level, maintains ISO 27001 certification, and provides HIPAA BAA, GDPR DPA, and comprehensive compliance documentation.
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence in this assessment was independently sourced from public registries, threat intelligence feeds, domain analysis tools, media archives, and certification databases without vendor participation.
4 findings identified for Salesforce
Between 2025 and August 2026, 15 separate security incidents were publicly reported across 17 publishers affecting Salesforce customers. Incidents include high-severity breaches at Infinite Campus (137,000 staff records), Cisco (3 million records), Pitney Bowes (25 million records), and Cushman & Wakefield (500k records claimed). …
The domain registration for salesforce.com expires in 53 days. For a Fortune 500 company, this is a routine administrative cycle, not a stability risk; however, failure to renew would be a catastrophic operational event.
A class-action lawsuit was filed in May 2025 alleging Salesforce was breached, affecting 1.1 million+ Farmers Group customers. The case is historical litigation related to a data compromise event, not an ongoing active enforcement or judgment.
In August 2026, Cybersecurity Dive reported that Salesforce's free security scanner (provided to all organizations) has known gaps that attackers are aware of and actively exploiting. This finding is alleged and has not been acknowledged by Salesforce or a regulator. …
Showing the 4 most severe of 6 findings.
Evidence that positively supports Salesforce's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
No Sanctions Matches Found
Sanctions & Watchlist Screening →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Salesforce complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Salesforce claims SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, FedRAMP (Government Cloud), HIPAA (Health Cloud), and PCI DSS compliance. Salesforce Government Cloud Plus is FedRAMP Certified at Class D (High) on the FedRAMP Marketplace. Given Salesforce's scale and the number of product families, organizations should verify that their specific clouds and connected apps fall within each relevant certification's scope.
ThirdProof investigated Salesforce across 27 intelligence sources. Historical media search identified critical adverse media related to the 2025 Gainsight OAuth and Drift-Salesforce token compromise incidents. Current threat intelligence is clean, SSL/TLS grade is A+, and sanctions screening is clear. The elevated risk rating is driven by the scale and recency of supply-chain incidents affecting Salesforce customer data via connected apps — review the full report to understand whether your specific connected apps were affected.
Represent Salesforce? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Salesforce assessment above is already written; ask for it and it lands in your inbox.