Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Agentforce and Einstein Generative AI
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          LLM Data Masking Considerations and Limitations

          LLM Data Masking Considerations and Limitations

          Make sure you review these considerations and limitations before configuring large language model (LLM) data masking,

          Required Editions

          Available in: Enterprise, Performance, and Unlimited Editions with an Einstein for Sales, Einstein for Platform, Einstein for Service, Einstein 1 Service, or Einstein GPT Service add-on. To purchase add-ons, contact your Salesforce account executive.

          Limitations

          • LLM Data Masking isn’t always available in all features. Refer to the feature documentation for more information.
          • Data masking for LLMs is disabled for agents. See Data Masking and Agents. For embedded generative AI features, such as Einstein Service Replies, Einstein Work Summaries data masking is available, and you can configure it in Einstein Trust Layer setup.
          • Pattern-Based Masking: Although our detection models have shown to be effective during internal testing, it's important to note that no model can guarantee 100% accuracy. In addition, cross-region and multi-country use cases can affect the ability to detect specific data patterns. With trust as our priority, we're dedicated to the ongoing evaluation and refinement of our models.
          • Field-Based Masking: Field-based masking is supported in Prompt Builder and AI features that use prompt templates. Field-based masking can only be used only for merge fields in prompts that reference record fields and related lists.

          Considerations

          Data masking can affect LLM prompt grounding. We recommend that you test any masking configurations to ensure high quality LLM responses. Use the audit trail to verify masking behavior.

          Consider these differences when configuing pattern-based and field-based masking:

          pattern-based field-based
          Automatic detection by Einstein Trust Layer based on pattern matching, context, or machine learning models. Detection is based on Data Classification tags in Salesforce fields configured by you.
          Applied to all text in the prompt, including unstructured inputs like freeform text, as well as merged information from Salesforce fields.

          Applied to only merge fields in prompt templates.

          Supported data sources: Record fields and related lists.

          Supports only a discrete list of data types and languages. Any field in Salesforce org can be classified and used for field masking.

          To make sure your data masking configuration is more comprehensive, apply data classification to Salesforce fields and turn on data masking in Einstein Trust Layer setup for the relevant classification types. Enabling pattern-based masking can be an additional layer of protection because it evaluates the entire text in the prompt for sensitive data.

          Pattern-based masking relies on model inference and carries inherent accuracy trade-offs. Unusual names or names in non-English formats aren't always detected reliably and require additional validation or a different masking strategy. When masking fails to detect a value, the unmasked data is included in the prompt sent to the large language model (LLM). Before deploying masking in production, test with representative sample data that includes edge-case names relevant to your users. For high masking accuracy, use field-based masking instead. Field-based masking operates on structured data fields directly and is more reliable than pattern-based detection.

           
          Loading
          Salesforce Help | Article