VendorScore · CRM · Data-access posture

Can Salesforce read your data?

A plain-language answer from Salesforce's public Trust & Compliance and Shield docs. Shield Encryption doesn't mean Salesforce can't read your data.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-06, public docs only, not legal advice.

Short answer

Yes. Salesforce processes customer CRM data and can decrypt Shield-encrypted fields when it holds or uses active tenant secrets/DEKs for the service. BYOK improves custody and revoke; it is not full zero-knowledge for the platform.

60 / 100 overall

Scored configuration: Sales/Service Cloud on Hyperforce/core with optional Shield Platform Encryption (including BYOK / customer key material).

Without Shield, the report estimates Overall ~50 (Salesforce-managed custody).

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score and key findings) · FAQ policy links re-checked 2026-10-07 · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Salesforce's public documentation:

  • SOC report details and any key-management scope exclusions aren't public. Get them under NDA.
  • Exact field coverage and feature limits of Platform Encryption are org-specific. Einstein/Agentforce and Data Cloud change data paths and need re-scoring if AI is in scope.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Salesforce data access, AI training, GDPR and residency

Can Salesforce read your data?

Yes. Salesforce processes customer CRM data and can decrypt Shield-encrypted fields when it holds or uses active tenant secrets/DEKs for the service. BYOK improves custody and revoke; it is not full zero-knowledge for the platform. VendorScore rates Salesforce 60/100 overall from public documentation (evidence dated 2026-10-06). Scored configuration: Sales/Service Cloud on Hyperforce/core with optional Shield Platform Encryption (including BYOK / customer key material).

Does Shield Platform Encryption or BYOK stop Salesforce reading my data?

No. Shield encrypts selected fields and files, but Salesforce still decrypts for authorized app operations when keys are available, and search, automation and AI need server-side processing. BYOK helps: destroying or revoking customer key material can make Shield-encrypted data inaccessible. While keys are active, Salesforce uses them to run the service.

Can Salesforce employees see my CRM data?

Yes, where their work requires it. Salesforce's Data Processing Addendum commits to "ensure that SFDC’s access to Personal Data is limited to those personnel performing Services in accordance with the Agreement, Order Form(s) and Documentation." Encryption doesn't prevent that, because Salesforce decrypts for authorized app operations when keys are available.

Does Agentforce or Einstein train AI on my data?

Not third-party models. Salesforce's Trusted AI page says the Einstein Trust Layer's "Zero data retention is a strict policy where the prompts and generated responses are never stored or used to train the underlying third-party large language models". The pages we reviewed don't state a general rule for Salesforce's own models, so check your AI terms. Einstein and Agentforce also change data paths and aren't covered by this score.

Is Salesforce GDPR compliant? Where is the Salesforce DPA?

VendorScore doesn't certify compliance; Salesforce publishes a DPA at https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/Agreements/data-processing-addendum.pdf. This Data Processing Addendum (revision August 2026) refers to the Standard Contractual Clauses and Salesforce's Processor Binding Corporate Rules (BCR) for transfers.

Who are Salesforce's subprocessors? Does OpenAI see my data?

Salesforce lists hosting and processing entities in its Infrastructure and Sub-processors document (published October 2, 2026) at https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/misc/salesforce-infrastructure-and-subprocessors.pdf, linked from its Trust & Compliance documentation. For several services the document lists OpenAI as a provider of generative artificial intelligence. Customers can subscribe to subprocessor change notifications.

Can I keep Salesforce data in the EU (Hyperforce EU Operating Zone)?

For authorized products, yes. Salesforce says the Hyperforce Operating Zone restricts data transfer outside the zone "by processing and storing customer data strictly within the region (EU and Switzerland)", with 24/7 support from EU-based personnel. Only products authorized for the Operating Zone are covered.

Compare Salesforce

All comparisons

Sources

Every URL cited on this page. Score and key findings: VendorScore report (salesforce.md), evidence dated 2026-10-06. FAQ policy links: vendor pages re-checked 2026-10-07.