Copies of every production record sitting in sandbox environments
Delete 1 record in production. It lives in 20–30 sandboxes. Unmasked. Accessible to every developer and contractor with sandbox access.
Sandbox data is treated as fake. It isn't.
of organizations experienced non-production data breaches
Full-copy sandboxes contain a complete copy of production data. Real names, real SSNs, real financial records. Developers, QA engineers, and offshore contractors log in and query it directly. 29% of companies use unprotected real data in testing environments. Most don't know until something goes wrong.
“When we copy the data into full copy Sandbox, any developer who can get access. They can see everything, all the PII data.”
Enterprise Architect
contractors blocked from sandbox access while security reviews run
Before a contractor can enter a full-copy sandbox, IT must sort security. That means a ticket, an approval, and a manual masking process if one exists at all. Development stalls. Deadlines slip. The contractor waits. 30% of data breaches now involve external partners.
“It can take up to a week or more to get someone set up in our sandboxes. Most contractors cannot enter full copy sandboxes.”
IT Security Lead
Salesforce Shield offers against sandbox PII exposure
Regulators do not distinguish between production and non-production breaches. GDPR fines reach €20 million or 4% of global turnover: for sandbox data the same as for production. The FTC has settled enforcement cases specifically for test environment security failures. A breach is a breach.
“Non-production environments fall outside of that boundary and are just not secured or monitored as well as your production systems.”
Salesforce Consulting Principal
Set rules once. Every refresh, every sandbox.
Field-Level Masking on Every Refresh
Masking rules execute automatically during sandbox refresh. No manual steps, no post-refresh scripts. Set rules once per field; DataMasker applies them every time, across every sandbox type.
Realistic Data, Not Real Data
Masked values maintain realistic distributions. Dates preserve age ranges, financial figures maintain income ratios, names generate plausible replacements. Testing works. AgentForce AI trains on data that behaves like production without being production.
Email and Callout Suppression
DataMasker mutes Salesforce automations during masking, preventing email blasts to real customers triggered by workflow rules, process builders, or flows running on refreshed data. External system callouts are also suppressed.
DevOps Integration via REST API
Trigger DataMasker from Copado, Flosum, Jenkins, Gearset, AutoRabit, or GitLab via REST API call. Sandbox refresh and masking run as part of your existing DevOps pipeline. No separate manual step required.
Battle tested on 4 continents.
99M Records Masked in 24 Hours
DataMasker processes 5M records per hour in production Salesforce orgs. No batching required. No performance degradation during refresh.
3 Weeks to Go-Live. Clicks, Not Code.
Setup uses a clicks-based interface with pre-built field-level masking templates for standard Salesforce objects. No Apex development required.
Contractors in Sandboxes in Hours, Not Weeks
Once masking rules are set, sandbox access for contractors is unblocked on every refresh automatically. No security review, no ticket, no wait.
How it works
CI/CD or sandbox refresh triggers DataMasker
A sandbox create, refresh, or CI/CD post-deployment hook triggers DataMasker automatically. No manual step or ticket required.
Salesforce copies production data into the sandbox
Salesforce copies production records into the sandbox org. DataMasker waits for the refresh to complete before beginning masking; users are blocked from access during this window.
PII replaced, automations muted
DataMasker executes all configured masking rules across every in-scope object. Sensitive data (names, SSNs, emails, financials) is replaced with realistic substitute values. Flows, Process Builders, and Apex triggers are suppressed to prevent outbound emails or callouts during the masking run.
Environment configured for safe use
After masking completes, DataMasker runs post-refresh cleanup: Remote Site Settings updated, user email addresses de-suffixed, and sandbox-specific settings applied. The environment is ready.
Users notified, sandbox unlocked
Developers, QA engineers, and contractors receive access notifications. The sandbox contains realistic-format data with no real personal information.
Regulations that apply to sandbox environments
DataMasker supports the compliance workflows that apply to Salesforce non-production environments. Automates processes. Does not guarantee outcomes.
General Data Protection Regulation
Article 5 data minimisation applies to non-production environments. Sandbox PII exposure creates GDPR obligations identical to production.
California Consumer Privacy Act
CCPA applies to all environments where California resident data is processed, including sandboxes.
Health Insurance Portability and Accountability Act
Protected Health Information (PHI) in sandboxes requires the same technical safeguards as production. HIPAA does not distinguish between environments.
SOC 2
Service Organization Control 2
Access control requirements for sensitive data apply to non-production environments containing customer records.
FINRA
Financial Industry Regulatory Authority
Financial data access controls and records management apply to sandbox environments at broker-dealer firms.
ISO 27001
ISO/IEC 27001
Information security management standards cover all environments where personal data is processed, including development and test.
Key Takeaways
Masks field values at the point of sandbox refresh, no post-refresh scripts needed
5M records/hour throughput, masks a full sandbox in hours, not days
100% native Apex, data never leaves your Salesforce org, no middleware required
Suppresses workflow automations to prevent email blasts to real customers during masking
Works with Full Copy, Partial Copy, and Developer sandboxes, all sandbox types supported
Frequently Asked Questions
Installation via Salesforce AppExchange takes under 5 minutes. Configure masking profiles through a point-and-click interface. Most teams complete their first sandbox masking run the same day.
No custom code needed for standard implementations. Configuration happens through Salesforce screens. REST API triggering requires connected app setup but no Apex coding.
Works with Enterprise, Unlimited, and Performance editions. Supports all sandbox types (Developer, Developer Pro, Partial Copy, Full Copy) and scratch orgs.
Initial deployment takes one business day. Full production deployment with CI/CD integration typically requires 1-2 weeks.
Yes, it has passed rigorous assessment covering OWASP Top 10, data handling, encryption, and access controls.
No, designed for non-production environments only. It eliminates PII exposure in developer and QA environments without modifying production.
Support for multiple named profiles allows creating Developer (aggressive masking), QA (selective masking), and Demo profiles with specific substitutions.
Requires System Administrator profile or custom profile with DataMasker permission set. Running user must have object access. No special license add-ons needed.
Supports realistic name generation, email substitution, phone masking, address masking, date offset, numeric range masking, picklist substitution, and regex pattern masking.
Cannot directly mask calculated fields. Masks source fields instead, automatically updating formula results. Contact Cloud Compliance for independent formula field scenarios.
Yes, substitutes values with other valid picklist options while preserving data integrity constraints.
Grouping and sequencing features process related objects together, ensuring consistent propagation of changes across related records.
Yes, filter conditions allow masking records matching specific criteria, useful for partial copy sandboxes preserving reference data.
Works alongside Shield. Shield encrypts at rest; DataMasker masks decrypted values with realistic substitutes.
Yes, masks the local part while preserving domain, useful when domain serves as company proxy.
Fully supported. Treats as unified Contact+Account object, applying masking rules simultaneously to both.
Yes, supports portal user records, community member data, and associated CRM objects.
Yes, all custom objects and fields are available in profile configuration.
Processes approximately 5 million records per hour. Scales to 99 million in 24 hours using parallel batch processing.
Uses Apex Batch with configurable sizes (default 200, tunable to 2,000). Spawns parallel jobs for large volumes.
Start with 200 records/batch for complex schemas. 500-1,000 safe for simpler schemas. Avoid maximum sizes with many relationships.
Yes, simultaneous jobs process different objects. Achieves 99M records in 24 hours through parallel batch processing.
1-5M records: 2-4 hours. 10-50M records: 8-12 hours with standard parallelism. Example: 125M records in 48 hours.
Runs asynchronously in background job queue. Sandbox remains accessible. Schedule during off-hours for large jobs.
Completed batches preserved. Resume feature allows re-running from failure point. All errors logged with record ID and field.
Yes, grouping and sequencing resolves FSC row-locking through dependency-aware processing.
Call REST API endpoint with masking job configuration. API returns job ID for polling completion status.
Yes, use post-deployment webhook feature to call REST API after sandbox deployment.
Yes, REST API supports HTTP requests from any CI/CD platform using curl or preferred HTTP client.
Specifies target sandbox, masking profile name, and optional overrides. Uses OAuth 2.0 connected app authentication.
Two methods: REST API trigger from CI/CD pipeline or Scheduled Apex. API recommended for active DevOps pipelines.
Yes, masks scratch orgs via REST API after org creation and data loading.
Poll REST API endpoint until completion. Response includes summary of objects, records, and fields processed plus errors.
Yes, profiles stored as Salesforce records. Subject to standard record-level access controls. Version control through metadata export.
Cloud Compliance provides documentation, API reference, sample integrations, and Customer Success Manager support.
See How DataMasker Is Used
HIPAA Compliance for Salesforce
OCR auditors require documented masking of PHI in test environments. See what HIPAA requires.
Healthcare: Salesforce Compliance
How healthcare orgs mask PHI across Health Cloud and Service Cloud sandboxes.
Agentforce Data Masking
Before you turn on AI agents: mask the training data they reason over.
Watch DataMasker Demo
See DataMasker mask 5M records in a 3-minute live demo walkthrough.


