Skip to main content
Skip to main content

Salesforce Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Salesforce before Salesforce sends a questionnaire or a security document.

Salesforce's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Salesforce — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Salesforce's own trust page.

FedRAMP Certified — Class D (High) Checked August 2026.

Salesforce Government Cloud Plus is FedRAMP Certified at Class D (High) via the JAB path (package FR2003061248). Commercial Salesforce orgs are not covered by this certification.

Risk
Tier 3Moderate Risk
Evidence confidence
100%
25 of 27 sources returned data
Questionnaire
79 / 133 answered
59% from public evidence
Last assessed
Aug 28, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 27.7 years🟢Infrastructure: 2 open ports, 0 CVEs
FedRAMP Status
Salesforce is listed on the FedRAMP Marketplace — Independently verified (checked August 2026).
SOC 2 Status
Salesforce — SOC 2: Vendor attested — trust page. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Salesforce returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Salesforce a Moderate Risk tier across 27 intelligence sources, 25 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 25 returning usable evidence. The Salesforce assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Salesforce Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

79 questions answered before Salesforce responds.

ThirdProof used public evidence to pre-fill 59% of a 133-question vendor security questionnaire — without waiting for Salesforce. The remaining 54 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

Salesforce is PCI DSS Level 1 certified service provider, meeting the most rigorous security standards for handling payment card data.

Public evidencehigh confidence

Q37

Do you have a current SOC 2 Type II report?

SOC 2 Type II: Vendor attested — trust page

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

Salesforce is GDPR compliant and provides a Data Processing Agreement (DPA) including European Commission Standard Contractual Clauses, authorized sub-processor list, and technical descriptions.

Public evidencehigh confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

Salesforce can be used in a HIPAA-compliant manner and provides a Business Associate Agreement (BAA) with specific restrictions and covered services listed at https://www.salesforce.com/company/legal/business-associate-addendum-restrictions.

Public evidencehigh confidence

Q23

Is data encrypted at rest? What encryption standard is used (e.g., AES-256)?

Salesforce Shield Platform Encryption uses Advanced Encryption Standard (AES) with 256-bit encryption for data at rest using strong, probabilistic encryption.

Public evidencehigh confidence

+ 74 additional evidence-backed answers

Get the Complete Salesforce Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Salesforce sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • FedRAMP — independently verified
  • No Sanctions Matches Found
  • FedRAMP Authorization Confirmed via Registry
  • FedRAMP Authorization Independently Verified
  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered

Still requires vendor confirmation

  • Current SOC 2 report and its audit scope
  • Access Control — 8 of 12 questions need vendor input
  • Data Security — 8 of 14 questions need vendor input
  • Incident Response — 7 of 10 questions need vendor input
  • Application Security — 5 of 7 questions need vendor input

Reviewing Salesforce for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Salesforce

Salesforce is a mature, enterprise-scale SaaS vendor offering customer relationship management (CRM) and related cloud services.

Area Requiring Attention

The vendor demonstrates strong positive signals across compliance, infrastructure, and security governance. Salesforce holds FedRAMP authorization at Moderate impact level, maintains ISO 27001 certification, and provides HIPAA BAA, GDPR DPA, and comprehensive compliance documentation.

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence in this assessment was independently sourced from public registries, threat intelligence feeds, domain analysis tools, media archives, and certification databases without vendor participation.

Investigation Findings

4 findings identified for Salesforce

1 high1 medium2 low
high

Customer environment compromises reported on the vendor's platform

Between 2025 and August 2026, 15 separate security incidents were publicly reported across 17 publishers affecting Salesforce customers. Incidents include high-severity breaches at Infinite Campus (137,000 staff records), Cisco (3 million records), Pitney Bowes (25 million records), and Cushman & Wakefield (500k records claimed). …

medium

Domain expiring soon

The domain registration for salesforce.com expires in 53 days. For a Fortune 500 company, this is a routine administrative cycle, not a stability risk; however, failure to renew would be a catastrophic operational event.

low

Litigation reported against the vendor (historical)

A class-action lawsuit was filed in May 2025 alleging Salesforce was breached, affecting 1.1 million+ Farmers Group customers. The case is historical litigation related to a data compromise event, not an ongoing active enforcement or judgment.

low

Security incident reported involving the vendor

In August 2026, Cybersecurity Dive reported that Salesforce's free security scanner (provided to all organizations) has known gaps that attackers are aware of and actively exploiting. This finding is alleged and has not been acknowledged by Salesforce or a regulator. …

Showing the 4 most severe of 6 findings.

Security Strengths

Evidence that positively supports Salesforce's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

No Sanctions Matches Found

Sanctions & Watchlist Screening

FedRAMP Authorization Confirmed via Registry

Certification Registry Verification

FedRAMP Authorization Independently Verified

Trust & Compliance Page Scan

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Salesforce complete vendor assessment

Tier 3
Moderate Risk
79 / 133
questionnaire answers
27
sources checked
Aug 28, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 28, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Salesforce Compliance and Certification Status

Salesforce claims SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, FedRAMP (Government Cloud), HIPAA (Health Cloud), and PCI DSS compliance. Salesforce Government Cloud Plus is FedRAMP Certified at Class D (High) on the FedRAMP Marketplace. Given Salesforce's scale and the number of product families, organizations should verify that their specific clouds and connected apps fall within each relevant certification's scope.

Salesforce Security Posture and Recent Incidents

ThirdProof investigated Salesforce across 27 intelligence sources. Historical media search identified critical adverse media related to the 2025 Gainsight OAuth and Drift-Salesforce token compromise incidents. Current threat intelligence is clean, SSL/TLS grade is A+, and sanctions screening is clear. The elevated risk rating is driven by the scale and recency of supply-chain incidents affecting Salesforce customer data via connected apps — review the full report to understand whether your specific connected apps were affected.

Frequently asked about Salesforce

Does Salesforce have SOC 2 Type II?+
Salesforce states that it maintains SOC 2 on its trust page. Because SOC 2 reports are generally confidential and there is no public SOC 2 registry, ThirdProof classifies this as vendor-attested until the current report and its scope have been reviewed. Request the report directly to confirm the audit period and which systems are in scope.
Is Salesforce on the OFAC sanctions list?+
Salesforce returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Salesforce's vendor risk tier?+
ThirdProof assigned Salesforce a risk tier of Moderate Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Salesforce.
Has Salesforce had any data breaches or security incidents?+
ThirdProof's assessment as of August 2026 records 2 incident-related findings for Salesforce, of which 1 is rated high severity or above. The most severe concerns customer environment compromises reported on the vendor's platform. Each finding states whether the incident affected Salesforce's own systems, a customer's environment, or a third party — a distinction that changes what you should ask about — and links to the source it was drawn from. The complete assessment carries all of them with their evidence.
Is Salesforce PCI DSS compliant?+
Salesforce is PCI DSS Level 1 certified service provider, meeting the most rigorous security standards for handling payment card data. ThirdProof records this from Salesforce's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does Salesforce support HIPAA and sign BAAs?+
Salesforce can be used in a HIPAA-compliant manner and provides a Business Associate Agreement (BAA) with specific restrictions and covered services listed at https://www.salesforce.com/company/legal/business-associate-addendum-restrictions. If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Salesforce security questionnaire?+
Yes. ThirdProof answered 79 of 133 questions (59%) about Salesforce from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 54 are listed as open, so the follow-up you send Salesforce is short and specific.
What evidence should I request from Salesforce?+
Public evidence settles a large part of the review, so the request you send should be short. Ask Salesforce for the current SOC 2 report and, where applicable, a bridge letter covering the period since the report date; the audit scope — which systems and services the report actually covers; written answers on access control, data security, incident response; contractual commitments, cyber insurance, and the current subprocessor list. Everything ThirdProof could already establish is recorded with its source, so you are not asking Salesforce to re-confirm what is already documented.

Represent Salesforce? Submit updated security evidence.

If Salesforce is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Salesforce assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required