You are here:
Specify Your Security Contact Information
Provide security contact information for timely updates and communications related to critical security issues.
Where to Specify Your Security Contact
How you update security contacts depends on your Salesforce product area and service tier.
- For Core clouds (Sales Cloud, Service Cloud, and Industry Cloud), Salesforce admins on any
Success Plan can update contacts directly in Setup.Note For incident notifications, Salesforce first checks the Company Information page in Setup. If no in-org contact is available, Salesforce falls back to the Security Contact listed in the Help and Training portal, and finally to the org admin.
The security contact receives automated detection and containment alerts for issues such as VPN or anonymizer detection, OAuth revocation, extended login anomalies, and unauthenticated guest user misconfigurations. If the alert contact field is empty, Salesforce sends these alerts to the admin.
- For other Salesforce clouds and products, Primary Designated Contacts (PDCs) on Signature or Premier Success Plans manage security contacts in Salesforce Help. These contacts receive security incident notifications, including Cybersecurity Operations Center (CSOC), Customer Response Engagement Security Team (CREST), and Security Response Center Comms (SRC) Comms.
- For Tableau, security notifications are sent to the Security Point of Contact managed via the Tableau Customer Portal. This field is separate from the Security Contact Information page in the Help and Training portal.
Update a Security Contact for a Core Org
For Core clouds, including Sales Cloud, Service Cloud, and Industry Clouds, set the required security contact information on the Company Information page in each production org. The information only applies to the org where you enter this information. This field is required.
In production orgs, Salesforce periodically prompts admins to add, verify, or review the security contact information. If your company has multiple production orgs, repeat these steps in each org.
- Log in to your production org.
- From Setup, in the Quick Find box, enter Company Information, and then select Company Information.
- Click Edit.
-
In the Security Contact Information section, enter the required information.
- For Name, enter the full name of the person responsible for security decisions.
-
For Email, enter a valid business email address for the security contact. You can enter
an individual email address or a distribution list. Don’t use a contractor’s company email
address.
Don’t use a personal email address. For a government account, use an email address on the .gov domain or another email domain that identifies the government agency.
- For Phone, enter a direct phone number where Salesforce can reach the named security contact for urgent communications. Don’t enter a general support line.
- Click Save.
Set an Account-Level Security Contact for Non-Core Products
For supported non-Core products, a Primary Designated Contact (PDCs) on a Signature or Premier Success Plan can add, edit, or delete account-level security contacts in Salesforce Help.
- Log in to Salesforce Help.
- Click your avatar and then select Support Settings.
- Select Your Org Information.
- In the Customer Security Contacts section, add, edit, or delete security contacts as needed.
Assign a Tableau Security Point of Contact
To designate a user as a Secure Point of Contact or Technical Point of Contact, modify the user’s permissions in the Tableau Customer Portal.
- Log in to the Tableau Customer Portal.
- On the Account Details page, edit the user whose permissions you want to update.
- Under Additional Permissions, select Security Point of Contact or Technical Point of Contact.
-
Save your changes.
For more information, see Manage Users in the Tableau Customer Portal.
