Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Salesforce, your compliance team needs documented proof they can be trusted. ThirdProof investigated Salesforce across 27 intelligence sources — here's what we found.
✓ FedRAMP Status: Authorized (Moderate) — verified against marketplace.fedramp.gov
27 sources queried. 100% confidence. Every Salesforce investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Salesforce's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 38% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
Salesforce has achieved ISO 27001 certification with 3-year renewal audits and annual surveillance audits.
Q41
FedRAMP authorized: Product: Salesforce Government Cloud; Provider: Salesforce; Status: Compliant; Impact Level: Moderate; Authorization Date: 2020-11-02T05:00:00.000Z
Q40
Salesforce offers a Business Associate Addendum (BAA) for HIPAA compliance and healthcare applications.
Q42
Salesforce provides a Data Processing Addendum (DPA) detailing data processing framework and legal requirements for GDPR compliance.
+ 3 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Salesforce's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Verified against the official FedRAMP Marketplace API as of March 2026.
Salesforce Government Cloud authorized at Moderate impact level.
Moderate Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
27
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for Salesforce
Automated narrative synthesis unavailable. 6 finding(s) identified by the rule engine for Salesforce.
Risk tier determined deterministically. Manual review recommended.
13 findings identified for Salesforce
Article from www.salesforceben.com: "Salesforce Hacks 2026: Everything We Know So Far | Salesforce Ben"
Article from cyberindemnity.org: "Hallmark's 2026 Salesforce Breach: Lessons in Cloud Security, Incident"
Article from www.bleepingcomputer.com: "Automaker giant Stellantis confirms data breach after Salesforce hack"
Article from www.bleepingcomputer.com: "ShinyHunters launches Salesforce data leak site to extort 39 victims"
Article from topclassactions.com: "Workday, Salesforce class action claims companies failed to protect consumer data"
4 Hacker News stories about "Salesforce" related to security incident. Top story: "Google suffers data breach in ongoing Salesforce data theft attacks" (207 points).
salesforce.com received a failing grade (F) from Mozilla HTTP Observatory. This indicates serious HTTP security configuration issues. Note: This scan was performed on the marketing site (salesforce.com). The application endpoint (login.salesforce.com) may have different security headers. Verify the application domain separately.
2 article(s) reference security or regulatory concerns for "Salesforce": "Salesforce Security Incident: Unauthorized Data Access via Compromised Gainsight..." (Rescana) https://news.google.com/rss/articles/CBMixgFBVV95cUxOS2ZxSjZ6WnBrbVgxTlRLR1NGWmNtRkhpRmd5dS1ZcnZ2N1FfQTZCS25PQUZxUzQ4Q0RIZ25FamFUV1lDYkpaa3lRQ05USnB6b29ab2RZNG1MblVaeER0eDBTWHVfNUlCaGlHY3VUeGpZdDB5eVAtNm1hTGFyYlhrZ1hDd0s3R1ZuSzBvUW5mZkRycVFrYkM2am1MbDAxRHVLT2pvSVJEY3B6d2JYNXFDRmxxc1RnSkNiNFhzYnQzNFJ4WDVRb3c?oc=5; "Hackers steal data from 200+ companies via Salesforce breach" (The Tech Buzz) https://news.google.com/rss/articles/CBMilwFBVV95cUxQenZubG5WZ3I4dnhlcjFZcnFQN0tyR2ItS3BnRkp4UElXX0lhTkdGbjVVNFlVNS1ZeFFHeHhlSHVtalBTR1dZVVNYdms1Zk02RUU1ai1ZWWxYNV85U19pY1RuQ1hiaWpDQUFYRXBGMEoxVGJSNHAxM3hfb25wdC1zSjZhVTRlWC1QbjY4X2MtUm84X3dmNXhz?oc=5
13 article(s) reference significant concerns for "Salesforce": "Cybersecurity News: Salesforce data leak, SimonMed breach, Chipmaker vs. Dutch g..." (CISO Series) https://news.google.com/rss/articles/CBMirgFBVV95cUxPVFMwT3VJd09MLXlhUjdWckN3NDhORm55Uktkckt2ME9TeTJrbVBSLXNGNlNDRTEtSTdfMFc5NTNFMFZaSFpHMTVTZG4zWTAxWFZmNW1NeEZXSllLREFXU29mR1dSUm1KSm9EblE4X3VkaGNPTGpHOV8zVEFWT3BWQVRyMFJKTXlDYlNIdGt6S0hQVi1ybzNEZFR0TTJzdTF3NnNXZnRkTFBjZDNQb2c?oc=5; "The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep" (Forrester) https://news.google.com/rss/articles/CBMiqwFBVV95cUxQNGRPWEdyeTQzTWprWVhVRmVZOEV6eTJya2hVWlhFS3RfRVJEc1hJNXE2V0kyTjB1X3hTbW1jWkxoaTFJem1XSFh2U1l2Tzd2T2VyenZQT1gzZ3BtTHdUM1NVLVJ2MmE2dF9mMjZYVnRKd0lOcXF0OUZqTmdiNTZMbzJMS2VZYWtLYzAxbzJMdmtldlJOcEtFa3VydUdjUjNHYmJHeklBaU1GRHc?oc=5; "Token Hijack: The Drift-Salesforce Breach that Shook SaaS" (KELA Cyber Threat Intelligence) https://news.google.com/rss/articles/CBMikgFBVV95cUxOZVRkMW15SnFyMWYtUjIzSDNlOEdqV0FoaTB0TFVoNXpXMExDMV9tbjVCX2JUaktEVnlvUTBMTDh6MFJwSGp4aExwMndDS2ZSMnJyWC1kVDVNZDBZUy11QW1kUXJqa2hEY2xHZVlTV3BYZFNCbzAzNWRZUGxwYlZRS0RyTll2N2lIY0hpZGdOR2NYUQ?oc=5
Article from www.claimsjournal.com: "Salesforce Sued By Authors Over Artificial Intelligence Software"
salesforce.com is missing 2 recommended security headers: Content-Security-Policy, X-Frame-Options.
salesforce.com has certificates from 37 different Certificate Authorities. This may indicate inconsistent certificate management practices.
salesforce.com has an AI-related policy page but does not clearly state whether customer data is used for AI model training.
24 positive signals verified
Legal Entity Actively Registered
Business Registration →Sanctions Data Incomplete
Sanctions & Watchlist Screening →Low-Confidence Sanctions Matches Only
Sanctions & Watchlist Screening →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (27+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →Tech Community Discussion: security
Tech Community Sentiment →Large Certificate Footprint (1157 subdomains)
Certificate Transparency →Web Presence: 2 Years
Web Archive History →Domain in 50 Threat Intelligence Pulses
Threat Intelligence (OTX) →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →Subprocessor Page Found, No Entries Parsed
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →FedRAMP Authorization Confirmed via Registry
Certification Registry Verification →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →Zero Data Retention for AI Processing
AI Data Usage Policy →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for Salesforce
Review rule engine findings manually
Re-run assessment when AI synthesis is available
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Salesforce? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Salesforce on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Salesforce's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Salesforce a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Salesforce appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Salesforce's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Salesforce's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Salesforce claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Salesforce depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Salesforce appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Salesforce claims SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, FedRAMP (Government Cloud), HIPAA (Health Cloud), and PCI DSS compliance. Salesforce Government Cloud holds FedRAMP Moderate authorization on marketplace.fedramp.gov. Given Salesforce's scale and the number of product families, organizations should verify that their specific clouds and connected apps fall within each relevant certification's scope.
ThirdProof investigated Salesforce across 27 intelligence sources and assigned a High Risk (Tier 2) rating with 82% confidence. Historical media search identified critical adverse media related to the 2025 Gainsight OAuth and Drift-Salesforce token compromise incidents. Current threat intelligence is clean, SSL/TLS grade is A+, and sanctions screening is clear. The Tier 2 rating is driven by the scale and recency of supply-chain incidents affecting Salesforce customer data via connected apps — review the full report to understand whether your specific connected apps were affected.
Seeing this in an audit? ThirdProof lets you investigate Salesforce and every other vendor in your stack — average report time: 7 minutes. Get Salesforce's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Salesforce across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.