Loading
Salesforce now sends email only from verified domains. Read More
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Salesforce Shield Platform Encryption Architecture

          Salesforce Shield Platform Encryption Architecture

          Salesforce Platform Encryption protects customer data by encrypting various data elements within the Salesforce platform, including fields, search indexes, and the database itself. This encryption provides you with enhanced data security and can help you meet compliance requirements.

          Required Editions

          Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
          Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
          Available for free in Developer Edition.

          This guide provides information on Shield Platform Encryption, not Classic Encryption. (What’s the difference?)

          Here's what we'll cover about Salesforce Platform Encryption.

          • General encryption details, our encryption philosophy, and considerations on implementing encryption policies in your org
          • Details and flow descriptions of the key management processes of each feature
          • Technical description of our key derivation architecture
          • Detailed descriptions of each of these encryption features available in Shield Platform Encryption:
            • Database Encryption, an example of encryption at the data tier.
            • Field-level encryption (FLE), an example of application-tier encryption.
            • Search Index Encryption.
          • Detailed descriptions of these key material types supported by Database Encryption, FLE, and Search Index Encryption
            • External Key Management (EKM).
            • Bring Your OwnKeys (BYOK).
            • Cache-Only Keys (CoK).
           
          Loading
          Salesforce Help | Article