Loading
Prepare for Email to Become the Default Login ExperienceRead More
Intermittent freezing when using using certain browser versionsRead More
Set Up and Maintain Your Salesforce Organization
Encrypt Data 360 with Customer-Managed Root Keys

Encrypt Data 360 with Customer-Managed Root Keys

By default, Salesforce encrypts all Data 360 data at rest with a Salesforce-managed data encryption key (DEK). With Platform Encryption for Data 360, you can generate and control a Data 360 root key in Salesforce. Your Data 360 root keys are specific to your org and secure the DEKs that encrypt and decrypt your data. In this way, you control the chain of keys that encrypt your data. If you want to generate or manage keys outside of Salesforce, you can also use Bring Your Own Key (BYOK) or Shield External Key Management (EKM).

Required Editions

Available in both Lightning Experience and Salesforce Classic (not available in all orgs).
Available in: Enterprise, Performance, Unlimited, and Developer Editions. Requires purchasing Salesforce Shield or Shield Platform Encryption, and the External Key Management Service. Data 360 customers must also have the Platform Encryption for Consumption license.
User Permissions Needed
To generate, destroy, export, import, upload, and configure key material: Manage Encryption Keys
To view and edit Setup: View Setup and Configuration

You can generate root keys that encrypt Data 360 data in both production and sandbox environments.

Important
Important Data 360 doesn’t encrypt external DLOs because they’re outside of Data 360.
  1. From Setup, in the Quick Find box, enter Encryption Settings, and then select Encryption Settings.
  2. Turn on Manage Data 360 Keys.
    Salesforce generates a root key for you. When it’s ready, you can see it on the Key Management page under the Data 360 tab. A root key-controlled DEK immediately starts encrypting new data in Data 360, including Data 360 search indexes.

    Salesforce automatically starts applying your root key to all previously-ingested data in Data 360. This sync process can take some time if you have a large amount of data. Monitor the encryption sync process on the Encryption Statistics page in Setup.

  3. You can optionally edit the description on your root for easier key identification and auditing. To edit the description:
    1. From Setup, in the Quick Find box, enter Encryption Settings, and then select Key Management.
    2. In the Root Key Inventory section under the Data 360 tab, click Details.
    3. Click Edit Description.
    4. Add a unique description, and then save your work.
  4. After your Salesforce root key finishes syncing to your Data 360 data, you can upload a root key or set up a connection to an external key store. See Connect Salesforce to AWS KMS and Create a Data Encryption Key and Bring Your Own Key (BYOK)
Note
Note Root keys don’t control the DEKs used to encrypt unstructured data flows in Data 360.

For Sub-Second Real-Time customers who require external key material encryption in Data 360, Salesforce uses tenant level isolation for storing encrypted keys for unified profiles. This isolation ensures that each tenant's data is encrypted with its own keys.

 
Loading
Salesforce Help | Article