Loading
Prepare for Email to Become the Default Login ExperienceRead More
Set Up and Maintain Your Salesforce Organization
Generate and Manage Root Keys and Tenant Secrets

Generate and Manage Root Keys and Tenant Secrets

Salesforce has multiple secret types that are used to encrypt different categories of data. You can generate root keys, data encryption keys, and tenant secrets right from Setup.

Required Editions

Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
Available for free in Developer Edition.
Note
Note This content relates to Shield Platform Encryption. Read about implementing field-level encryption using Shield Extension in Own from Salesforce.
  • Shield Platform Encryption Key Material Types
    Encrypt data with either tenant secrets, a key pair composed of a root key and a data encryption key (DEK), or a DEK that you upload. Each type of key material targets specific data stores within Salesforce. You can apply different key-rotation cycles or key-destruction policies to different keys based on the kinds of data that they encrypt.
  • Generate a Tenant Secret with Salesforce
    For new customers and admins setting up field-level encryption, generate your first probabilistic and deterministic tenant secrets from the Encryption Settings page. You can also generate any tenant secret from the Key Management page.
 
Loading
Salesforce Help | Article