Salesforce Einstein
medium riskEmbedded SaaS AIsalesforce.comverified 2026-06-27
Data-handling profile
- Trains on input
- Yes, on the consumer tier (enterprise tier excluded)
- Retention
- Einstein Trust Layer enforces zero data retention with third-party LLM providers (prompts/completions not stored or used for provider-side training). Separately, unless an org admin opts out via Setup, Salesforce may use org data in aggregate to train its own global predictive AI models; opt-out does not degrade functionality.
- Data region
- Global
- Certifications
- SOC 2 Type IIISO 27001
- DPA available
- Yes
- Breach history
- 2025 ShinyHunters/ShinyLeaks social-engineering campaign compromised numerous customer Salesforce instances (via vishing and OAuth-connected apps like Salesloft/Drift and Gainsight), exposing large volumes of CRM data across hundreds of organizations; Salesforce attributes root cause to phishing/third-party integration abuse, not a platform vulnerability.
- EU AI Act
- Agentforce autonomous agents used in customer-facing decisions (e.g., service, credit-adjacent workflows) may trigger high-risk classification depending on use case; enterprise customers must assess per deployment.
Sources
- https://trailhead.salesforce.com/content/learn/modules/the-einstein-trust-layer/meet-the-einstein-trust-layer
- https://vantagepoint.io/blog/sf/salesforce-opt-out-customer-data-access-einstein-ai-training
- https://www.blackfog.com/the-salesforce-breach-wave-of-2025/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.