You are here:
Data Classification and Protection in Government Cloud
Salesforce Government Cloud Plus provides a layered approach to data governance—from classifying fields by sensitivity level to encrypting data at rest, tracking change history for forensic audits, and masking sensitive information before it reaches AI models or sandbox environments. Understanding these capabilities helps your agency select and implement the right protections for your compliance posture and data handling requirements.
Required Editions
| Available in: Enterprise and Unlimited Editions |
| Version | 1.0 |
| Last Updated | May 2026 |
Data Classification metadata in Salesforce allows customers to tag and categorize the data they store based on its sensitivity and the compliance regulations that govern it. By classifying data, Salesforce administrators define the intent of their data which allows this metadata to act as an "instruction manual" for advanced security tools such as Salesforce Shield and the Einstein Trust Layer. Data Classification enables customers to categorize data based on the following metadata fields:
- Data Sensitivity Level: Categorizes the risk associated with a field, such as Public, Internal, Confidential, or Restricted.
- Compliance Categorization: Tags fields that fall under specific regulatory frameworks like HIPPA, GDPR, PII, PHI, or PCI.
- Data Owner: Identifies the user or group responsible for the governance of that data set.
- Implementation: These values are assigned at the field level via Setup or programmatically using the Metadata API.
Advanced Data Protection and Governance
Once data is classified, customers can implement tiered governance to expand the protection of their data. This can be divided between standard platform tracking and advanced enforcement through Salesforce Shield.
Salesforce Shield
Salesforce Shield is a suite of security products that builds extra levels of security, compliance, and governance into your business-critical apps.
- Shield Platform Encryption: Allows customers to natively encrypt data within Salesforce at varying levels of granularity while managing encryption key material. Customers can utilize Platform Encryption to encrypt data at rest, such as fields, files, using AES 256-bit encryption, while maintaining critical business functionality like search and validation.
- Field Audit Trail: An enhancement to standard tracking that allows customers to know the state and value of their data for any date at any time. Field Audit Trail allows for the monitoring of up to 60 fields per object and allows data to be retained until the customer manually deletes it, ensuring long-term forensic auditability.
- Event Monitoring: Provides customers valuable insight into who's accessing data and how, where data is being accessed from, and the ability to build policies that proactively keep data secure.
Data Masking (AI & Sandboxes)
To help protect data when it is processed by Generative AI (Prompt Builder) or moved to non-production environments, customers that are administrators in their Salesforce Org can utilize Data and Field Masking provided through the Einstein Trust Layer and Salesforce Data Mask.
The Einstein Trust Layer is a secure AI architecture, built into the Salesforce platform. It's a set of agreements, security technology, and data and privacy controls used to keep your company safe while you explore generative AI solutions.
- Field Based Masking: Uses Data Classification metadata to identify and mask specific fields before a prompt is sent to a Large Language Model (LLM). This ensures sensitive data is kept sensitive.
- Pattern-Based Masking: Employs machine learning to detect and mask data following specific formats, such as Social Security Numbers, even if they aren't explicitly tagged.
Salesforce Data Mask
Data Mask is a platform-native obfuscation technology that is used to mask sensitive customer data in any full or partial sandbox. When sandbox data is masked, customers can't unmask it. This irreversible process ensures that the data isn't replicated in a readable or recognizable way into another environment. Production data remains unaffected, however customers can always refresh the data from production and create a sandbox org.
- Classify and Protect Data in Government Cloud
Configure data classification settings, enable field change tracking, and implement advanced data protections in your Salesforce Government Cloud Plus org. These procedures walk you through tagging fields by sensitivity and compliance category, enabling Field History Tracking, and reviewing Salesforce Shield.

