To ensure the confidentiality and availability of customers' data, the B2C Commerce platform takes a holistic approach to data security. We are constantly monitoring our service to ensure that systems are running properly, and resolving problems before they impact customers’ storefronts. Our approach to data security allows customers to leverage our service where they see fit, and follow their own internal security processes and procedures in a complimentary fashion. Security is an evolving element of our service, and we approach each potential threat as a threat not only on our customers, but to our company.
The B2C Commerce platform's PODs are collocated at top-tier data centers around the world. These locations are audited as part of our PCI compliance. They provide services to us, including:
TLS 1.0 and 1.1 have been disabled for inbound & outbound for B2C Commerce platform. TLS 1.2 and 1.3 are supported as outlined below:
Any password strength or session parameters are PCI compliant
Salesforce applies general operational security (OPSEC) principles to administering and maintaining the security posture of the B2C Commerce platform. This includes periodic threat assessments and customized countermeasure development, if appropriate. Additionally, all Salesforce employees authorized to access the B2C Commerce platform undergo a comprehensive background check, as permitted by applicable regulations.
Salesforce tests any release for security vulnerabilities as part of our QA process. In addition as part of PCI compliance we monitor security mailing lists and OWASP threat profiles. We also do penetration tests and vulnerability scans internally and external to our service. Customers are encouraged to follow their own security procedures and test their storefront as part of their compliance efforts.
There is continuous testing of our service internally and from at least three external locations to ensure system availability. The B2C Commerce platform is designed to ensure that any component failure (drive, networking, processor etc.) doesn't compromise the availability of a customer’s storefront, but only the total capacity of that storefront. As part of the monitoring we are constantly evaluating any security risks that customers would encounter as part of their normal day to day operations and notifying customers as needed.
000391174

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.