Trust is Salesforce’s number one value. It is the foundation on which every customer relationship is built, and the lens through which our security team evaluates every decision we make. That mission hasn’t changed. But the environment in which we defend it has changed dramatically, and faster than most security organizations ever anticipated. Our customers’ ability to innovate hinges on the security of the Salesforce platform and their data. We are working to stay ahead of the rapidly changing threat landscape with continued security enhancements to our products and services and by enabling our customers as we work together to meet our shared responsibility.
Over the past months, the threat landscape has undergone a continued structural shift. AI hasn’t just made attacks more convenient; in the hands of capable adversaries, it has fundamentally altered the physics of exploitation. We want to be transparent about what we’ve seen, what we’ve built in response, and what we’ve learned.
A New Normal: Attacks at Machine Speed
The compressed speed of cyberattacks matters significantly. The data you store in those systems — customer records, financial data, health information — is exactly what sophisticated attackers are after. A faster exploit lifecycle means the window between a vulnerability and an attempted breach has shrunk to hours. Our collective job is to close that window before it opens.
In the past, security teams typically had a more predictable window to patch vulnerabilities, often with several weeks between vulnerability disclosure and weaponization, allowing time to remediate before exploitation occurred. Today, the time from discovery to active exploitation can be measured in hours. And the force behind that compression isn’t a new class of attacker; its attackers are using AI to cover substantially larger surfaces, find weaknesses, and build exploits faster than ever before.
In June 2025, XBOW topped HackerOne’s leaderboard — marking the first autonomous AI-powered system to outperform every human hacker on the platform. By November 2025, state-sponsored actors were running fully autonomous attack chains across dozens of global targets. By February 2026, an AI system had surfaced 500+ high-severity open source vulnerabilities and found 12 zero-days in OpenSSL independently.
In April 2026, frontier cyber AI models were publicly announced alongside reports of thousands of zero-days across every major OS and browser. These models raised the ceiling further — a reminder that the frontier models available to attackers and defenders alike will keep advancing, and that the program we build today has to anticipate the capabilities of tomorrow.
How Frontier AI Models Changed Our Security Program
As we continue to harden our defenses against accelerating threats, Salesforce is actively involved in industry-shaping efforts to help defenders find and fix vulnerabilities before they can be exploited. We participated in Project Glasswing and joined a recent call for collective action on cyber defense. Frontier models like Claude Mythos and OpenAI’s GPT-5.5-Cyber, and tools to find and patch vulnerabilities like Google’s CodeMender, can give security teams new ways to understand emerging risks, strengthen resilience, and keep improving the platforms customers depend on every day.
By working with the most advanced security models to secure our platform, we’re not just keeping pace with the frontier — we’re shaping how the industry can reinforce customer trust. The same models available to the most sophisticated attackers in the world are now working around the clock on your behalf to protect your data.
Our Response: Four Workstreams
Our vulnerability management and security operations have always been built for scale. Now, agentic AI helps us contain threats at machine speed. Frontier AI has raised the bar, and we raised it further. We organized our work into four areas, each designed not only to enhance our own operations, but to ensure the platform our customers run their businesses on remains resilient against AI-speed threats.
Reduce known security debt. We re-triaged our entire backlog through an AI-era exploitability lens, asking not “is this theoretically exploitable?” but “can an AI-assisted attacker chain this with two other moderate findings to reach critical data?” We took this analysis and began executing a series of architectural changes to eliminate entire attack surfaces and classes of attack.
Accelerate vulnerability discovery using frontier models. We operationalized frontier AI models for vulnerability discovery across our portfolio, finding issues in the code that powers your integrations and apps before attackers can.
Enable high-velocity remediation. We redesigned our remediation service level objectives (SLO) framework, introduced automated fix-and-deploy pipelines, and removed approval bottlenecks from the critical path to update software faster than ever before without compromising quality. For tactical remediation, we built agentic harnesses that develop, test, and stage fixes for vulnerabilities across our entire portfolio.
Agentic security operations. Fixing software vulnerabilities isn’t enough, so we brought agentic AI systems into our Cybersecurity Operations Center, helping us shift from ticket-driven vulnerability management toward continuous, AI-driven vulnerability operations. Now, we can detect and contain an increasing number of threats at machine speed and with far greater fidelity than before.
Security best practices
Curious about more ways to bolster the security of your Salesforce org? Check out our guide for additional guidance and resources
Critical Lessons from Our Deployment
Speed of resolution matters as much as speed of discovery. AI finds vulnerabilities fast — which we learned quickly is the easier part. We redesigned our response processes to match the pace of the threat, cutting timelines and removing friction from the path between a confirmed finding and a deployed fix.
Getting the foundation right took time, and it was worth it. Deploying AI responsibly, in a way that genuinely protects our internal systems and our products, requires getting governance right before scaling.
Finally, volume without precision isn’t protection. We built a rigorous validation process to ensure only confirmed, exploitable vulnerabilities reach our engineering teams, because precision is what makes a security program powerful.
What This Means for Your Data
We want our customers to focus on the secure deployment and maintenance of their Salesforce orgs, not on rebuilding your Salesforce operations around AI-speed threats. We’re already doing that. The changes we’ve described here are live, and we’re doing more every day. AI models scan our platform for vulnerabilities continuously, not on a quarterly pen-test cadence. When we find something, we fix it faster than ever before. And when the threat landscape shifts again — and it will — we’ve built a program designed to adapt, not react.
Innovating Against Tomorrow’s Threats
Our work doesn’t end here. As frontier AI continues to evolve, so will the ways we deploy it to protect our customers. We’re investing in deeper automation, more sophisticated agentic security operations, and closer coordination across the industry, because Trust is our #1 value — which means staying ahead of the threat landscape isn’t a milestone, it’s a commitment.
We also recognize that Salesforce isn’t the only organization that can benefit from using AI systems to defend itself. That’s why we share our practices through industry groups like the ISACs and by convening CISOs and security leaders. In May 2026 we convened our inaugural CISO Summit at Salesforce Tower in San Francisco.
We’re going to continue pushing the boundaries of what autonomous defense looks like at enterprise scale, and are committed to sharing what we learn. Every capability we build, every process we compress, every vulnerability we close before it can be exploited — it all serves the same goal: making Salesforce the most trusted platform in the world to run your business on. That standard drives everything we build.
Join us at Dreamforce 2026










