CSA STAR Registry
Security, Trust, Assurance, and Risk Registry
Listings for Salesforce.com, Inc.
Salesforce.com, inc. (“Salesforce”), headquartered in San Francisco, California, is an enterprise
cloud computing company that provides social and mobile cloud services. Controls described in this document only apply to the core Salesforce Services.
The Salesforce Services are branded as Force.com, Site.com, Database.com, Sales Cloud, Service Cloud, Communities, Chatter, and Analytics Cloud. Salesforce provides services to companies of all sizes via a cloud services model. This collection of application development, deployment, and hosting services allows customers the ability to purchase, use, and customize Salesforce deployed applications, or use platform capabilities to develop their own applications. The Salesforce Services information system includes the Force.com environment which is a part of the App Cloud offering, as well as applications built on top of the platform including the Customer Relationships Management (CRM) Application, Chatter, and the supporting Salesforce Services’ infrastructure. Force.com provides each customer with the capability to implement business logic with workflow rules, approval processes, and custom code. Customers can store structured data, support Web browsers and mobile devices, integrate their services with other applications, perform their own reporting and analytics, and scale up or down with high availability and security. There are more than 150,000 customers worldwide who use the Salesforce Services for managing their sales, marketing, customer support, and various other business operations.

Salesforce.com, Inc.
Listed Since: 2016-03-13

EU Cloud CoC
This trustmark signifies adherence to the EU Cloud CoC through a dedicated framework and legally demonstrates GDPR compliance. Cloud Service Providers that have successfully passed the EU Cloud CoC’s evaluation process have their Compliance Mark visible in both the Code’s Public Registry as well as here in the CSA STAR Registry.
AI CAIQ
Offers an industry-accepted way to document what security controls exist in solutions that include AI components or are AI products. It provides a set of Yes/No questions a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Artificial Intelligence Controls Matrix (AICM).
Organizations who have the CSA Trusted
Cloud Provider trustmark demonstrate
a commitment to organizational security. They are
a CSA
Corporate Member, volunteer regularly for
CSA, and have at least one staff member who has
earned their CCSK.