📈 Read the 2025 Salesforce Threat Landscape Report

Cloud Protection for Salesforce by WithSecure™
  • Home
  • Product
    • Product overviewLearn how WithSecure protects your Salesforce from advanced cyber threats.
    • File protectionDefend your organization against malware and ransomware attacks.
    • URL protectionPrevent phishing and malicious URL attacks with real-time protection.
    • Identity protectionDetect compromised users before attackers.
    • Protection for AgentforceSecure Agentforce workflows in real-time from phishing and malware.
    • Analytics and visibilityGet comprehensive real-time visibility into security events.
    • QR code protectionIdentify and block QR codes leading to phishing sites.
    • Content filteringBlock unwanted files and URLs.
    • All featuresExplore product features in detail.
  • Solutions
  • Customers
  • Pricing
  • Resources
    • SupportHow to install, configure and troubleshoot the product.
    • Events & webinars4 upcomingWhere are we headed next? See our upcoming schedule.
    • ComplianceSee what certifications we have and how we comply with regulations.
    • BlogGet the latest product updates and Salesforce security insights.
    • DatasheetsAccess our datasheets, solution overviews and other collaterals.
    • For partnersLet’s deliver more value to Salesforce customers – together.
    • Risk assessmentGet your free Salesforce content risk assessment.
    • About usLearn who we are, why we do what we do and how it all started.
  • Contact sales
  • Get a demoClaim your free 15-day trial
  • English
    • English
    • 日本語 (Japanese)
  • Contact sales
  • Get a demoClaim your free 15-day trial
  • ANALYTICS AND VISIBILITY

    Analytics and security visibility in Salesforce

    See every file, link, and user action inside Salesforce. Investigate faster, prove compliance, and stop threats flying under the radar.

    Full forensics trails

    Out-of-the-box and custom reports

    Book a demo

    Visibility gaps in Salesforce create security risk

    Without visibility during an incident, teams often have only one option: freeze the environment to stop the malicious activity they can’t trace.

    That means downtime, lost productivity, and customers left waiting.

    You can’t protect what you don’t see

    In Salesforce, files and links are exchanged nonstop across users and workflows.

    Traditional email security and endpoint protection tools don’t monitor what happens inside Salesforce. If a file with malware gets in, you do not see it.

    Without security visibility on Salesforce, you risk:

    • Operations freezing during investigations, halting users and workflows
    • Investigations stalling without a clear trail of who uploaded or clicked what
    • Compliance teams lacking the audit-ready reporting regulators expect
    • Security teams missing early warning signs of phishing or malware moving through Salesforce

    Real-time visibility and full forensics trails on Salesforce

    Because it runs natively in Salesforce, WithSecure Cloud Protection records every upload, download, link, and detection – complete with who, what, where, and when.

    It also surfaces when user credentials are known to be exposed, so you can see risky accounts alongside content events and act before access is abused. The result is faster investigations without freezing the org, plus exportable, audit-ready evidence with long-term log retention for compliance.

    Learn more about credential compromise monitoring

    Enterprise-grade visibility

    Salesforce native dashboards and reports

    Prebuilt and custom dashboards give instant visibility into protection status and detection trends.

    24-month log retention

    Detailed event data is stored on Salesforce for long-term investigations and audits.

    Role-based access

    Granular permissions control for who can view and export reports.

    Audit-ready reports

    Generate detailed reports on-demand to support compliance checks.

    Multi-cloud coverage

    Sales Cloud, Service Cloud, Experience Cloud, and Agentforce all included.

    SIEM integration

    Seamless export of detection data to enterprise SIEM and SOAR systems.

    Certified and compliance-ready

    WithSecure Cloud Protection for Salesforce supports governance and compliance requirements by providing complete audit trails. Logs are anonymized, encrypted in transit and at rest, and processed in-region where required. We follow strict security processes, and are certified accordingly.

    Trusted by Fortune 500 enterprises and regulated industries.

    See our certifications

    Frequently asked questions

    Why do I need dedicated visibility in Salesforce?

    When you can’t see inside Salesforce, every second costs more. During an incident, lack of visibility inside Salesforce can paralyze response. Without clear telemetry, investigations stall — leaving security teams no choice but to freeze the entire environment to prevent further damage.

    That means halted workflows, disconnected users, and downtime that ripples across sales, service, and customer operations.

    Salesforce holds some of the most valuable data in the enterprise. Traditional security tools don’t monitor what happens inside Salesforce. Files are uploaded, shared, and downloaded, and links are posted and clicked — often by external users. Without native visibility, threats like malware deliveries and phishing link clicks can go unnoticed, investigations stall, and compliance evidence is incomplete.

    WithSecure Cloud Protection for Salesforce offers that visibility. Every upload, download, and detection is logged in real time, giving you the context – who, what, when – you need to respond fast without halting the business.

    Is there a lag in visibility?

    WithSecure Cloud Protection for Salesforce provides constant real-time visibility without time lags, with complete audit trails of what happened, who was involved, and where. When you have real-time visibility to your Salesforce:

    • You can investigate incidents immediately while mitigating further damage
    • You can conduct faster and cheaper investigations with full forensic trails (e.g. who, what, when)

    What kinds of analytics capabilities does WithSecure Cloud Protection for Salesforce offer?

    Dynamic analytics and reporting in WithSecure Cloud Protection for Salesforce gives a holistic security overview of Salesforce content and an opportunity to follow your security strategy in action.

    Rich reporting, advanced security analytics, and full audit trails help your security team to respond to threats in Salesforce and to investigate attacks.

    Out-of-the-box dashboards like the Protection Status dashboard provide a situational overview at a glance. You can leverage Salesforce’s powerful native reports and dashboards to create your own.

    What information is included in forensic logs?

    Logs capture every detail needed for investigations and audits, including:

    File SHA-256 checksum

    Verdicts from each detection engine

    File type, size, and extension

    URL categories and classifications

    Action (upload, download, post, click)

    Direction (inbound/outbound)

    User IDs, profiles, and roles

    Timestamps and IP addresses

    Object details (where the file or link was stored)

    Can I create custom reports?

    Yes. All log fields are available in Salesforce Reports. Security teams can build reports filtered by verdict, file type, user, detection engine, or URL category. Custom notifications and user messages can also be configured.

    How do automated alerts work?

    With WithSecure™ Cloud Protection for Salesforce, you can automate reports of security incidents and receive timely email alerts to administrators and your security department. This ensures prompt response and mitigation of potential threats.

    Alerts in WithSecure Cloud Protection for Salesforce are triggered when:

    Harmful or disallowed content is detected

    A scan result changes from safe to unsafe

    A file or URL is blocked during upload or click

    A disallowed file type is uploaded

    Configuration or license status changes

    Alerts can be sent to Salesforce admins, routed to IT security teams, or pushed into SIEM/SOAR systems.

    How long is event data retained?

    Event data is stored natively in Salesforce for up to 24 months. This supports long-running investigations and regulatory audits. Logs can also be exported or pushed to, for example, SIEM systems for extended storage.

    Can this help with compliance audits?

    Yes. Complete audit trails, long-term retention, and exportable reports support ISO 27001, ISAE 3000 Type 2, SOC 2 Type 2, HIPAA, and other regulatory frameworks.

    How is sensitive data handled?

    All data is anonymized and encrypted in transit and at rest. Logs never expose private Salesforce content. Processing can be regionalized (EU, US, Singapore, Australia, Japan) to meet data residency requirements.

    What is the protection status dashboard?

    The protection status panel provides a comprehensive, straightforward snapshot of your Salesforce security status, including file and URL scanning configurations, connectivity status, automatic update status, and the version in use. Thus, you can quickly spot and fix any security hiccups.

    The panel is neatly divided into four sections:

    • File Protection section shows the status of scanning and blocking harmful and disallowed content. Accessing File Protection settings is as easy as a click.
    • URL Protection section serves as your window into the status of harmful and disallowed URL scanning features.
    • Automatic Update section displays the status of automatic updates, along with the app version you’re currently using. You can see if automatic updates are enabled or disabled, and whether a manual installation of a newer version is needed.
    • Connectivity section provides a snapshot of the status of the connected app and its link to the WithSecure Security Cloud. This includes the status of seamless data exchange between your environment and WithSecure’s security services. You can see if the WithSecure Security Cloud is operational, not operational, or if its status is unknown. Similarly, you can see if the connected app is operational, not set up, malfunctioning, or if its status is unknown.

    You can see the status of critical security configurations in the Salesforce UI

    How does the alerts feed work?

    From the Alerts tab, you can access a comprehensive feed of all security-related events that have triggered alerts. This includes threat detections, scan overusage, and security configuration changes. If you suspect that you might have missed an alert, you can easily check the latest status here.

    You can see full audit trails of URL scan results and detected phishing threats on your Salesforce

     

    You can find detailed forensics information from the File Events and URL Events feeds about specific threat detections and scanning results. Full audit trails give you the complete picture. This includes details such as what happened, where, when, and by whom – for example, if a user clicked a phishing link or a malware was uploaded by an attacker.

    You get visibility to a specific file's history in a single view.

    Get a Free Demo

    THE #1 SALESFORCE MALWARE PROTECTION SOLUTION

    Fill the form and get:

    Free 15-day trial – test the product without limitations

    Real attack simulation and product demo

    Free customized and actionable risk assessment

    Cloud Protection for Salesforce

    Required field.

    Please enter a valid business email address.

    Invalid field.

    Required field.

    Enter your first and last name, separated by a space.

    Required field.

    Invalid field.

    Required field.

    Invalid field.

    Phone number can only contain numbers, spaces, and these special characters: + () -.

    Required field.

    Invalid field.

    Error sending form.

    We process the personal data you share with us in accordance with our Corporate Business Privacy Policy.

Product

  • Book a demo
  • Product
  • Solutions
  • Customers
  • Pricing

Resources

  • Blog
  • Events & webinars
  • For partners
  • Compliance
  • Datasheets
  • Risk assessment

Company

  • About us
  • W/ Elements

Support

  • Support portal
  • User guides
  • Release notes
  • Product lifecycle
  • English
    • English
    • 日本語 (Japanese)

Terms of service

Privacy

Product privacy policy

Modern slavery statement

Cookies