Salesforce Shield

Salesforce Shield — What’s Included, How It Works, and How to Implement

Learn about our suite of data security products that can help you monitor, encrypt, and classify your data with ease.

10 Key Reasons to Implement Salesforce Shield on Day 1
Discover how Shield helps you maximize data security and compliance from day one.

Here’s an overview of how Shield encryption compares to classic encryption.

Feature Classic Encryption Shield Platform Encryption
Encryption strength 128-bit AES 256-bit
Field support Limited standard fields Standard and custom fields
File and attachment encryption Not supported Fully supported
BYOK (Bring Your Own Key) Not available Supported
Report and filter compatibility Limited May restrict usage of encrypted fields in filters or views
Salesforce mascot Astro standing on a tree log while presenting a slide.
Stay up to date on all things security and privacy.

Sign up for our monthly newsletter to get the latest research, industry insights, and product news delivered straight to your inbox.

Astro standing in front of screen that reads Einstein Sales Emails.
Take our free Trailhead module to learn all about Shield's powerful suite of security products.

Salesforce Shield FAQs

Salesforce Shield includes four core components: Platform Encryption, Field Audit Trail, Event Monitoring, and Data Detect. Together, these products help you secure sensitive data, monitor user activity, and support compliance across your Salesforce environment. For a full breakdown, visit the Salesforce Shield security guide.

Salesforce Shield pricing varies depending on your Salesforce edition and user count. For the most accurate pricing based on your organization’s needs, check the Shield Pricing or contact your Salesforce account executive.

Salesforce Shield offers Platform Encryption using AES 256-bit encryption, which supports both standard and custom fields, as well as files and attachments. You can choose Salesforce-managed encryption keys or use the Bring Your Own Key (BYOK) option for additional control. This is distinct from classic encryption, which supports fewer fields and doesn’t allow BYOK.

No, data masking is not included in Salesforce Shield. However, Salesforce offers other tools (such as data masking in sandboxes) to help you anonymize sensitive data during development and testing. Shield focuses on live data protection through encryption, monitoring, and auditing.

Yes, Salesforce Shield is designed to integrate with other tools. For example, event monitoring logs can be exported to SIEM platforms for centralized monitoring, and audit trails can complement external compliance solutions. This flexibility allows you to embed Shield into a broader enterprise security ecosystem while maintaining strong native protections.