Salesforce AI Vendor Risk Profile

Enterprise CRM leader that combines proprietary AI models (Einstein, CodeGen, xGen) with OpenAI integration for Einstein GPT, embedding AI across sales, service, and marketing clouds.

Visit Salesforce website

HQ: United States · Hybrid

Risk overview

Risk score: 13/100

Risk tier: Low

Safety rating: 87/100 (higher is better)

Lower risk scores indicate lower assessed risk.

Last verified: Apr 19, 2026 (107 days ago) Aging · 8 cited sources

Risk dimensions

DimensionRisk score
Data Handling14/100
IP Exposure10/100
Jurisdiction13/100
Security18/100
Regulatory Compliance10/100
Transparency10/100
Business Stability10/100
Dependency Chain14/100
Agent Governance60/100

Analyst summary

Rating: Recommended

Salesforce's Einstein Trust Layer is the clearest example of an enterprise vendor engineering zero-retention pass-through to third-party LLM providers. For customers already on Salesforce, Agentforce and Einstein AI slot into existing compliance perimeters (SOC 2, ISO 27001, FedRAMP High) without new data-handling exposure.

Bottom line: A clean extension of Salesforce's existing trust envelope for Salesforce-standardized customers.

Strengths

Concerns

Best for

Avoid if

Citations

  1. Data Handling — Hipaa Baa Available (primary · high confidence)
    https://compliance.salesforce.com/en/documents/a005g00000XnxOGAAZ
    Verified 2026-04-19
    Salesforce offers a HIPAA Business Associate Agreement for Health Cloud and other eligible services.
  2. Data Handling — Outputs Feed Model Improvement (primary · high confidence)
    https://www.salesforce.com/artificial-intelligence/einstein-trust-layer/
    Verified 2026-04-19
    Salesforce's zero-data-retention architecture means no customer prompts or outputs are stored by third-party LLM providers.
  3. Data Handling — Trains On User Data (primary · high confidence)
    https://www.salesforce.com/artificial-intelligence/einstein-trust-layer/
    Verified 2026-04-19
    The Einstein Trust Layer ensures customer data is not retained or used to train models by third-party LLM providers.
  4. Ip Profiles — User Owns Outputs (primary · high confidence)
    https://www.salesforce.com/company/legal/agreements/
    Verified 2026-04-19
    Customer retains ownership of all Customer Data, including outputs generated from Customer Data by Einstein AI features.
  5. Jurisdiction Profiles — Incorporation Country (official · high confidence)
    https://investor.salesforce.com/sec-filings/
    Verified 2026-04-19
    Salesforce, Inc. is a Delaware corporation headquartered in San Francisco, California (SEC Form 10-K).
  6. Security Compliance — Fedramp Authorized (primary · high confidence)
    https://compliance.salesforce.com/en/fedramp
    Verified 2026-04-19
    Salesforce Government Cloud Plus holds FedRAMP High authorization.
  7. Security Compliance — Iso 27001 (primary · high confidence)
    https://compliance.salesforce.com
    Verified 2026-04-19
    Salesforce holds ISO/IEC 27001, 27017, 27018, and 27701 certifications.
  8. Security Compliance — Soc2 Type2 (primary · high confidence)
    https://compliance.salesforce.com
    Verified 2026-04-19
    Salesforce Services maintain SOC 2 Type II attestations available via the Compliance portal.