VendorScore · CRM · Data-access posture
A plain-language answer from Salesforce's public Trust & Compliance and Shield docs. Shield Encryption doesn't mean Salesforce can't read your data.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-06, public docs only, not legal advice.
Short answer
Yes. Salesforce processes customer CRM data and can decrypt Shield-encrypted fields when it holds or uses active tenant secrets/DEKs for the service. BYOK improves custody and revoke; it is not full zero-knowledge for the platform.
Scored configuration: Sales/Service Cloud on Hyperforce/core with optional Shield Platform Encryption (including BYOK / customer key material).
Without Shield, the report estimates Overall ~50 (Salesforce-managed custody).
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
Shield Platform Encryption supports Salesforce-generated tenant secrets and customer-supplied key material (BYOK / EKM / cache-only keys). Salesforce derives org-specific keys and uses data encryption keys in memory for service operations.
Evidence: Shield customer key options, Encryption processHosting and processing entities are listed in Salesforce's unified Infrastructure & Sub-processors document, and customers can subscribe to subprocessor notifications.
Evidence: Trust & Compliance documentationOur report flags these gaps in Salesforce's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes. Salesforce processes customer CRM data and can decrypt Shield-encrypted fields when it holds or uses active tenant secrets/DEKs for the service. BYOK improves custody and revoke; it is not full zero-knowledge for the platform. VendorScore rates Salesforce 60/100 overall from public documentation (evidence dated 2026-10-06). Scored configuration: Sales/Service Cloud on Hyperforce/core with optional Shield Platform Encryption (including BYOK / customer key material).
No. Shield encrypts selected fields and files, but Salesforce still decrypts for authorized app operations when keys are available, and search, automation and AI need server-side processing. BYOK helps: destroying or revoking customer key material can make Shield-encrypted data inaccessible. While keys are active, Salesforce uses them to run the service.
Yes, where their work requires it. Salesforce's Data Processing Addendum commits to "ensure that SFDC’s access to Personal Data is limited to those personnel performing Services in accordance with the Agreement, Order Form(s) and Documentation." Encryption doesn't prevent that, because Salesforce decrypts for authorized app operations when keys are available.
Not third-party models. Salesforce's Trusted AI page says the Einstein Trust Layer's "Zero data retention is a strict policy where the prompts and generated responses are never stored or used to train the underlying third-party large language models". The pages we reviewed don't state a general rule for Salesforce's own models, so check your AI terms. Einstein and Agentforce also change data paths and aren't covered by this score.
VendorScore doesn't certify compliance; Salesforce publishes a DPA at https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/Agreements/data-processing-addendum.pdf. This Data Processing Addendum (revision August 2026) refers to the Standard Contractual Clauses and Salesforce's Processor Binding Corporate Rules (BCR) for transfers.
Salesforce lists hosting and processing entities in its Infrastructure and Sub-processors document (published October 2, 2026) at https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-infrastructure-and-subprocessors.pdf, linked from its Trust & Compliance documentation. For several services the document lists OpenAI as a provider of generative artificial intelligence. Customers can subscribe to subprocessor change notifications.
For authorized products, yes. Salesforce says the Hyperforce Operating Zone restricts data transfer outside the zone "by processing and storing customer data strictly within the region (EU and Switzerland)", with 24/7 support from EU-based personnel. Only products authorized for the Operating Zone are covered.
Every URL cited on this page. Score and key findings: VendorScore report (salesforce.md), evidence dated 2026-10-06. FAQ policy links: vendor pages re-checked 2026-10-07.