{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"salesforce","name":"Salesforce","domain":"salesforce.com","category":"CRM","one_liner":"Salesforce, Inc. is an American enterprise software company headquartered in San Francisco, California","trust_center_url":"https://trust.salesforce.com/","security_page_url":null,"url":"https://certreports.com/vendors/salesforce/security","last_verified_at":"2026-09-19T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 19 Sep 2026.","kind":"authorization","status_text":"FedRAMP Authorized","issued_at":"2020-05-27","expires_at":null,"period_start":null,"period_end":null,"auditor":"Coalfire Systems, Inc.","impact_level":"High","as_of":"2026-09-19","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/salesforce/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2003061248","fetched_at":"2026-09-19 08:30:01.700532+00","content_hash":"b2bb3e031fda16f1f3201a5640ae64a639a15e4997f9d1ca43ef13a2942600e6","wayback_url":null,"quote":"Salesforce - Salesforce Government Cloud Plus: FedRAMP Authorized","confidence":1}]}],"brief":{"summary":"Salesforce is listed in the FedRAMP registry as FedRAMP Authorized, as of 19 Sep 2026. The FedRAMP authorization for Salesforce was issued 27 May 2020, as of 19 Sep 2026. The FedRAMP listing for Salesforce names Coalfire Systems, Inc. as the assessing auditor, as of 19 Sep 2026. No expiry date is recorded for Salesforce's FedRAMP listing, as of 19 Sep 2026. No public evidence was found for SOC 2, ISO/IEC 27001, HIPAA or GDPR for Salesforce, as of 19 Sep 2026.","bullets":["FedRAMP - listed in the FedRAMP registry as Authorized since 27 May 2020, as of 19 Sep 2026 (auditor: Coalfire Systems, Inc.)","No expiry date recorded for Salesforce's FedRAMP listing, as of 19 Sep 2026","No SOC 2, ISO/IEC 27001, HIPAA or GDPR evidence found for Salesforce, as of 19 Sep 2026"],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-19 10:42:42.472859+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T12:38:38.139Z"}