Search is a feature integrated into your Salesforce org. Search index encryption
supplies encryption keys specifically for your search indexes, protecting any sensitive
information within them. You can turn it on and off at any time. You can also rotate the root
key, data encryption key (DEK), or tenant secret.
Required Editions
Available in both Salesforce Classic (not available in all orgs) and Lightning
Experience.
Available in: Enterprise, Performance, and Unlimited
Editions with the Salesforce Shield or Shield Platform Encryption licenses.
Available for free in Developer Edition.
Prepare to Use Search Index Encryption
We recommend that you take these steps before you get started.
Plan to test your encrypted search in a sandbox thoroughly before migrating your
production org.
First Use of Search Index Encryption
Salesforce can create search indexes as soon as you begin using your org. When you turn on search
index encryption, any plain text indexes are encrypted in place.
Most Salesforce products use traditional keyword indexing. Einstein Search enhances this
experience with AI-powered personalization and natural language query processing, but it’s a
keyword search. Shield Platform Encryption secures the search indexes across Salesforce's
standard (non-Data 360) platforms.
Note Salesforce search index encryption isn’t the same as Data 360 search. Salesforce
Data 360 uses vector search for semantic understanding and powering sophisticated AI
features. Platform Encryption for Data 360 is responsible for encrypting the unique vector
search indexes within Data 360 itself.
Turning off Search Index Encryption
If you decide to turn off search indexes encryption, Salesforce gradually decrypts search
indexes. This process isn’t immediate, but usually completes within seven days.
Rotating Search Index Encryption Key Material
When you rotate your search index keys, Shield Platform Encryption archives your existing keys.
We never destroy them. There’s no background sync for search indexes. Instead, your search
indexes are gradually encrypted with the new DEK or tenant secret.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.