Skip to main content
Webinar Recording

Secure 360: Holistically Secure Your Salesforce Org & Data

A comprehensive walk-through of enterprise Salesforce security — org hardening, field-level security, sandbox access controls, and data masking. Build a defense-in-depth strategy covering both production and non-production environments.

Salesforce orgs have evolved from simple CRM into systems of record storing PHI, financial records, integration credentials, and sensitive customer PII — yet most organizations rely on a patchwork of controls that were not designed for this scope. Presented live at the Slalom Fort Worth community, this session walks through a four-step holistic security framework: assess your org health, secure your applications, secure your data, and build a security-aware culture.

Book a Demo

What's covered in this webinar

A Four-Step Framework for Holistic Security

  • Step 1 — Assess: use free built-in tools (Health Check, Portal Health Check, Optimizer) before spending on anything
  • Step 2 — Secure applications: IP restrictions, MFA, connected app controls, integration governance, code scanning
  • Step 3 — Secure data: data retention policies, Shield encryption, AI/ChatGPT exposure, sandbox masking
  • Step 4 — Improve awareness: make security training mandatory and a continuous cycle for every team member

Org Assessment & Application Security

  • Health Check, Portal Health Check, and Salesforce Optimizer are free tools in every org — most teams never run them
  • Over 70% of orgs with Salesforce Experience Cloud have publicly shared objects external users can access without authorization
  • API access control is not enabled by default — enabling it requires a Salesforce support ticket; without it any connected app can authenticate using stolen credentials
  • Integration users should use dedicated minimal-access profiles with JWT OAuth flows; the new API user license ($10–15/month) reduces exposure significantly
  • Salesforce Scanner and Checkmarx identify SOQL injection, cross-site scripting, and with/without sharing issues in Apex code before they reach production

Shield: What It Does and Doesn’t Do

  • Shield Platform Encryption encrypts data at the database layer; the customer owns the encryption key — the primary use case is contractual key ownership obligations
  • Shield does NOT protect against authorized users or compromised credentials — if someone has access, they see the data regardless of encryption
  • Event Monitoring provides near-real-time tracking of user activity, report exports, login events, and community interactions — the single best Shield investment for most orgs
  • Enhanced Transaction Security Policy allows real-time blocking of suspicious actions such as mass report exports or login from unexpected locations

Data Security: Production, AI, and Sandboxes

  • Data retention is now a legal obligation — CPRA (California), GDPR, and other regulations mandate you have and enforce a retention policy
  • ChatGPT risk: OpenAI’s own terms confirm they can view submitted data and use it for model training — regulated industries cannot simply block access without killing productivity
  • Cloud Compliance GPT5.ai anonymizes PII before sending context to ChatGPT and restores it in the response, keeping sensitive data inside the Salesforce perimeter
  • Full and partial copy sandboxes replicate all production data; even Dev sandboxes contain all user email addresses, phone numbers, and SSO federation IDs
  • DataMasker replaces real data with realistic fake values natively within Salesforce — 100 million records in 24 hours, fully automatable via Copado and CI/CD pipelines

Use this when

✓Your team has never run a formal security assessment of your Salesforce org and needs a systematic starting point without outside consultants.

✓You are evaluating Salesforce Shield and need to understand what it actually protects before committing to the purchase.

✓Your organization uses ChatGPT or generative AI tools and you are not sure whether employees are sending Salesforce customer data to external models.

✓Your developers work with sandbox data and you cannot confirm that real customer PII or PHI is masked before they access it.

✓You need to automate sandbox data masking as part of a CI/CD or DevOps release pipeline with no manual steps.

✓Your organization has multiple Salesforce orgs and needs a consistent security policy applied across all of them.

✓You need to demonstrate sandbox data governance to an auditor for SOC 2, HIPAA, or FedRAMP compliance.

Frequently Asked Questions

Ready to see this in your Salesforce org?

Book a 45-minute session and we'll walk through this use case using your own data and configuration.