Loading
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          What Gets Encrypted?

          What Gets Encrypted?

          You can encrypt a variety of fields, files, and data with Shield Platform Encryption. Salesforce uses metadata to keep information in these files and fields secure while preserving the ability to perform common business tasks.

          This table compares the features of Classic Encryption, application tier encryption, and data tier encryption:

          Item Classic Encryption Application Tier Encryption Data tier Encryption
          Pricing Included in base user license Additional fee applies Additional fee applies
          Encryption at Rest Checkmark Checkmark Checkmark
          Native Solution (No Hardware or Software Required) Checkmark Checkmark Checkmark
          Encryption Algorithm 128-bit Advanced Encryption Standard (AES) 256-bit Advanced Encryption Standard (AES CBC) 256-bit Advanced Encryption Standard (AES GCM)
          HSM-based Key Derivation Crossmark Checkmark Checkmark
          Manage Encryption Keys Permission Crossmark Checkmark Checkmark
          Generate Keys Checkmark Checkmark Checkmark
          Store Encryption Keys Outside of Salesforce Crossmark Checkmark Crossmark
          Export, Import, and Destroy Keys Checkmark Checkmark Crossmark
          Advanced Key Options Crossmark BYOK, Cache-only Keys, External Key Management BYOK
          PCI-DSS L1 Compliance Checkmark Checkmark Checkmark
          Masking Checkmark CrossmarkNo (Why Isn’t my Encrypted Data Masked?) CrossmarkNo (Why Isn’t my Encrypted Data Masked?)
          Mask Types and Characters Checkmark Crossmark Crossmark
          View Encrypted Data Permission Required to Read Encrypted Field Values Checkmark Crossmark Crossmark
          Encrypted Standard Fields Crossmark

          Checkmark

          Limited (What Standard Fields Can You Encrypt?)

          Checkmark

          All standard fields

          Encrypted Attachments, Files, and Content Crossmark Checkmark Checkmark
          Encrypted Custom Fields Dedicated custom field type, limited to 175 characters

          Checkmark

          Limited (What Custom Fields Can You Encrypt?)

          Checkmark

          All custom fields

          Encrypt Existing Fields for Supported Custom Field Types Crossmark Checkmark Checkmark
          Encrypt Custom Metadata and Apex Crossmark Crossmark Checkmark
          Search, Filters, and Queries Crossmark

          Checkmark

          UI, partial search, lookups, and certain SOSL queries on fields encrypted with the deterministic encryption scheme

          Checkmark

          All SOSL and SOQL queries except on fields also encrypted with field-level encryption

          Sorting Crossmark Crossmark

          Checkmark

          Except on fields also encrypted with field-level encryption

          Encrypt the Entire Database Including Standard and Custom Fields, Metadata, and Apex Crossmark Crossmark Checkmark
          API Access Checkmark Checkmark Checkmark
          Available in Workflow Rules and Workflow Field Updates Crossmark Checkmark Checkmark
          Available in Approval Process Entry Criteria and Approval Step Criteria Crossmark Checkmark Checkmark
          • What is Encrypted with Database Encryption?
            Database Encryption encrypts the entire transactional database. All data stored within the database is encrypted to include standard and custom entities, all metadata, all setup configuration data, chatter posts, Einstein data, transaction logs, and storage catalogs.
          • What is Encrypted with Field-Level Encryption?
            In contrast to Classic Encryption, which uses a custom field type in the Salesforce data model, Shield Platform Field-Level Encryption makes more fields, files, and data elements available for encryption with every release.
          • What is Encrypted with Search Index Encryption?
            The Salesforce search engine is built on the open-source enterprise search platform software Apache Solr. The search index, which stores tokens of record data with links back to the original records stored in the database, is housed within Solr.
          • What is Encrypted with Files and Attachments Encryption?
            Shield Platform Encyrption encrypt all files and attachments uploaded into Salesforce. The body of each file is ecrypted. If you have enabled Database Encryption, files and attachments smaller than 32K in size are stored directly within the transactional database and are under its encryption protection. Larger files are always stored as encrypted binary objects in a separate content store.
          • What is Encrypted with Event Change Data Encryption?
            The event bus may store event and CDC data in temporary files as it flows through integrations and real-time processes. Turning on Event Bus Data encryption ensures that event bus data in these temporary storage locations is fully encrypted.
          • What is Encrypted with CRM Analytics Encryption?
            When you enable CRM Analytics Encryption, all new reports, dashboards, and data sets are protected.
          • What is Encrypted with Chatter Encryption?
            Chatter Encryption is an application tier encryption that covers data in feed posts and comments, questions and answers, link names, and URLs. It also includes poll choices and questions and content from your custom rich publisher apps.
           
          Loading
          Salesforce Help | Article