Loading
Prepare for Email to Become the Default Login ExperienceRead More
Set Up and Maintain Your Salesforce Organization
Learn About Encrypting Data 360

Learn About Encrypting Data 360

By default, Salesforce encrypts Data 360 data at rest with a Salesforce-managed data encryption key (DEK). With Shield Platform Encryption, you generate and manage a tenant-specific root key that controls your DEK. In this way, you retain control and visibility over the keys that secure your data. Shield Platform Encryption for Data 360 also supports Marketing Cloud Next and Tableau Next wherever they use Data 360.

Required Editions

Available in both Lightning Experience and Salesforce Classic (not available in all orgs).
Available in: Enterprise, Performance, Unlimited, and Developer Editions. Requires purchasing Salesforce Shield or Shield Platform Encryption, and the External Key Management Service. Data 360 customers must also have the Platform Encryption for Consumption license.
Note
Note As of October 14, 2025, Data Cloud has been rebranded to Data 360. During this transition, you may see references to Data Cloud in our application and documentation. While the name is new, the functionality and content remains unchanged.

When you initially turn on encryption for Data 360, Salesforce generates a customer-managed key for you. This key is your Salesforce root key. You can also generate a key outside of Salesforce and upload it through the Bring Your Own Key process. With External Key Management (EKM), you apply keys stored in an AWS KMS account to your Data 360 data. With Platform Encryption for Data 360, all Data 360 data stores are encrypted with the same data encryption key. This coverage extends to Data 360's own vector-based search indexes, which are separate from Salesforce org keyword-based search indexes.

Important
Important Data 360 doesn’t encrypt external DLOs because they’re outside of Data 360.
 
Loading
Salesforce Help | Article