← Trust Directory

Salesforce

salesforce.com · 1 assessment

Salesforce
Approve with conditions
1 item to confirm in writing
Assessed Aug 31, 2026 · public evidence coverage 45% · evidence confidence medium · methodology 0.7.0

Assessed before company and product grades were shown separately; see the product assessments below.

Products assessed

A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.

Agentforce
Approve with conditions
1 item to confirm in writing
Assessed Aug 31, 2026 · public evidence coverage 45% · evidence confidence medium · methodology 0.7.0

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

EU-U.S. Data Privacy Framework
Claimed & corroborated

Salesforce publishes a Data Privacy Framework certification notice. Not corroborated against the official participant list in this collection.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Aug 31, 2026

APEC CBPR
Vendor claimed only

APEC CBPR and PRP certification notices are published alongside the Trust and Compliance Documentation.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
ISO/IEC 42001
Not claimed

Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current
FedRAMP Authorization
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Aug 31, 2026

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

AI providers: Microsoft Corporation (Microsoft Azure), OpenAI, L.L.C.
Infrastructure: Amazon Web Services, Inc.

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Aug 31, 2026.