📈 Read the 2025 Salesforce Threat Landscape Report

Cloud Protection for Salesforce by WithSecure™
  • Home
  • Product
    • Product overviewLearn how WithSecure protects your Salesforce from advanced cyber threats.
    • File protectionDefend your organization against malware and ransomware attacks.
    • URL protectionPrevent phishing and malicious URL attacks with real-time protection.
    • Identity protectionDetect compromised users before attackers.
    • Protection for AgentforceSecure Agentforce workflows in real-time from phishing and malware.
    • Analytics and visibilityGet comprehensive real-time visibility into security events.
    • QR code protectionIdentify and block QR codes leading to phishing sites.
    • Content filteringBlock unwanted files and URLs.
    • All featuresExplore product features in detail.
  • Solutions
  • Customers
  • Pricing
  • Resources
    • SupportHow to install, configure and troubleshoot the product.
    • Events & webinars5 upcomingWhere are we headed next? See our upcoming schedule.
    • ComplianceSee what certifications we have and how we comply with regulations.
    • BlogGet the latest product updates and Salesforce security insights.
    • DatasheetsAccess our datasheets, solution overviews and other collaterals.
    • For partnersLet’s deliver more value to Salesforce customers – together.
    • Risk assessmentGet your free Salesforce content risk assessment.
    • About usLearn who we are, why we do what we do and how it all started.
  • Contact sales
  • Get a demoClaim your free 15-day trial
  • English
    • English
    • 日本語 (Japanese)
  • Contact sales
  • Get a demoClaim your free 15-day trial
  • SALESFORCE ANTIVIRUS | MALWARE-PROTECTION | FILE SCANNING

    Advanced protection against malware and ransomware

    WithSecure Cloud Protection scans every file in Salesforce in real time, blocking malware, ransomware, and hidden cyber threats before they reach your users.

    Detects zero-day malware

    AV-TEST awarded engines

    Book a demo

    Salesforce is a blind spot for malware

    Your Salesforce environment accepts files from anyone: employees, customers, and partners. Your users can upload malicious files loaded with malware to your Salesforce via forms, emails, or apps. Those files are trusted by default, but Salesforce doesn’t scan them for malware or cyber threats.

    Perimeter defenses like email gateways or endpoint antivirus don’t reach inside the platform. Once a malicious file is uploaded to your Salesforce instance, it can spread across it before anyone realizes.

    That gap makes Salesforce an attractive target: attackers know they can bypass your existing security stack and distribute malware where users least expect it.

    Next-gen antivirus inside Salesforce

    Dynamic protection

    Detect both known malware and sophisticated zero-day attack methods.

    Fast detection

    Scan every upload and download in real time, without slowdown for users.

    Proven effectiveness

    Engines are validated by AV-TEST: 100% detection against commodity and zero-day malware.

    Real-time visibility

    Get clear alerts, recommended actions, and audit-ready logs.

    How File Protection works

    Files enter Salesforce and introduce risk

    File uploads come in through Experience Cloud, Service Cloud, Sales Cloud, email-to-case, Agentforce use cases and integrations. Malware hidden in PDFs, Office docs, image files or archives bypass perimeter defenses and land directly inside Salesforce.

    WithSecure Cloud Protection for Salesforce blocks malicious files
    Stop ransomware with antivirus for Salesforce

    Scan every file in real time

    WithSecure Cloud Protection for Salesforce scans each file at the moment of upload or download – across standard and custom Salesforce objects and fields. Files are analyzed against global threat intelligence bases. Unknown files are analyzed in-depth with next-gen antivirus engines, heuristics, and behavioral threat analysis, All in isolated sandbox environments.

    Block threats instantly

    When malware is detected, the file is stopped before anyone can open or share it. Users see a clear notification, and admins get instant alerts with recommended actions. Blocked files can be replaced with safe “notice files,” so workflows continue without disruption.

    Fast response to Salesforce cyber threats
    Hunt threats with Salesforce audit trails

    Visibility for security teams

    Every detection is logged with full detail. Admins get audit-ready reporting, possibility for SIEM/SOAR integration, and the ability to trace incidents back to the source. Instead of blind spots, you gain actionable visibility inside Salesforce. This means empowering real-time threat hunting.

    Award-winning anti-malware engines

    WithSecure Security Cloud powers File Protection with award-winning anti-malware engines, consistently rated “Best Protection” by AV-TEST. Backed by real-time telemetry from millions of endpoints and cloud systems, it delivers proven accuracy against both common and zero-day malware.

    WithSecure™ Security Cloud analyzes over 8 million files per day

    The service processes more than 5 billion client requests daily

    Algorithms are constantly tweaked by analysts and new threat data

    Under the hood: how every file is analyzed

    Every file uploaded into Salesforce is inspected through multiple detection layers in the WithSecure Security Cloud. This multi-step process combines speed, depth, and accuracy to stop both common malware and advanced zero-day threats before they spread.

    1. Fingerprinting & cache check

    Each file gets a unique fingerprint and is matched against an always-updated reputation cache for instant results.

    2. Threat intelligence lookup

    Unknown files are checked against global threat intelligence drawn from millions of endpoints and cloud systems.

    3. Multi-engine scanning

    Multiple antivirus engines analyze files in real time, catching both known malware and suspicious patterns.

    4. Sandboxing for zero-days

    High-risk files run in a secure sandbox where hidden exploits and zero-day threats are exposed safely.

    Protection applies across Salesforce Sales Cloud, Service Cloud, Experience Cloud, and Agentforce workflows, covering every file interaction from upload to download.

    Certified and audit-ready

    Trusted by public sector organizations, Fortune 500 enterprises, and highly regulated industries.

    See our certifications

    Advanced file security capabilities

    Detect and block malicious files across your Salesforce instance

    File Protection is a feature of WithSecure Cloud Protection for Salesforce. It scans every file that enters or moves through Salesforce, across Sales Cloud, Service Cloud and Experience Cloud, and including both standard and custom objects.

    Files uploaded through forms, cases, portals, emails, APIs or automations are analyzed in real time using multi-engine antivirus, heuristics, and sandboxing behavioral analysis. The NextGen Antivirus for Salesforce detects and blocks malware, ransomware, file type spoofing, and even malicious links hidden inside files – including behind QR codes.

    It also covers advanced scenarios such as password-protected archives and large files, ensuring threats are stopped before they reach users or cause disruption.

    Integrate real-time threat intelligence

    The Security Cloud constantly learns and adapts to emerging threats by harnessing real-time global threat intelligence. It proactively monitors and responds to new threats instantly, ensuring swift and effective protection across all user devices. As the system detects new threats, it updates its database and algorithms continuously. The system updates automatically in the cloud and requires no manual updates.

    Additionally, we integrate unique data from our partnerships with Fortune 500 companies to enhance our threat detection capabilities. This collaborative approach enriches our threat database, and as a result provides broader protection in an evolving digital threat landscape.

    Detect zero-day threats with behavioral threat analysis

    Even if initial scans and reputational checks fail to identify a file as malicious, a suspicious profile triggers a deeper investigation. In such cases, the file goes to a securely isolated sandbox environment in Security Cloud. Security Cloud analyses the file in-depth by performing behavioral assessments. This behavior-based threat analysis identifies even highly sophisticated threats like zero-day malware.

    WithSecure™ Cloud Protection for Salesforce governs file sandboxing through a proprietary set of rules designed to optimize threat detection. These rules consider a range of indicators within the files, including behavioral patterns and other suspicious activity.

    By combining both static and dynamic analysis in antivirus capabilities, we minimize false positives and ensure accurate threat detection on Salesforce. The result is a comprehensive and nuanced understanding of the sample, which significantly enhances our ability to identify and counteract threats.

    Detect malicious QR codes

    QR codes embedded in documents and images are inspected for malicious destinations. Obfuscation such as shortened links inside the code is detected and blocked. This closes a growing phishing vector that targets mobile devices and bypasses user training.
    Learn more in the dedicated QR code protection page. CThe protection cvers both QR code images and embedded QR codes in other file types like PDFs.

    Detect malicious URLs hiding inside files

    Attackers hide links in PDFs, Office documents, and other formats. File Protection extracts and evaluates embedded URLs, including those behind redirects or shorteners. Dangerous destinations are blocked before users open or share the file.

    These vectors are also a common delivery path for ransomware payloads, which can lock critical Salesforce data and connected systems if not stopped at upload.

    Wipe out executables with file type filtering

    You can block entire categories of risky formats by extension or true type. Common examples include executables such as EXE and COM, script files such as VBS and PS1, and other high-risk formats. Policies stop these files at upload so they never circulate in Salesforce.

    Stop file type spoofing with intelligent file type recognition

    Detection looks at the actual file content and structure, not only the extension name of the file. This prevents spoofing where an executable is renamed as a PDF or image. Precision recognition reduces false negatives and closes a common evasion path.

    Detect and block out password protected archives

    Password-protected archives commonly conceal malware, offering attackers a method to evade scanning by traditional anti-malware solutions like endpoint protection. This poses a significant risk, particularly in highly targeted industries. WithSecure™ Cloud Protection for Salesforce proactively addresses this threat with its advanced feature that detects and blocks password-protected archives in real-time.

    These vectors are also a common delivery path for ransomware payloads, which can lock critical Salesforce data and connected systems if not stopped at upload.

    Protect large files

    Uploads up to 800 MB are supported without degrading user experience. Scanning reaches inside nested archives and container formats to expose hidden malware. This covers for example large media assets used in enterprise workflows.

    Max out efficiency with automated threat removal

    When a file is confirmed malicious, the upload is blocked immediately. You can replace it with a notice file (.txt) that explains what was stopped and when. Users stay informed and workflows continue, while administrators receive actionable alerts.

    Scan in real-time and on-demand

    Our real-time protection on Salesforce scans files for threats both when users upload them to the platform, and whenever they download them. With this proactive approach, WithSecure Cloud Protection for Salesforce can effectively block evolving threats such as polymorphic malware types.

    Admins can run manual sweeps across existing Salesforce content. Scheduled scans ensure older files and seldom-touched records are re-evaluated under current policies. This reduces residual risk from historical uploads and policy changes.

    Stay compliant with strict data handling protocols

    User privacy is a top priority for us. Data is anonymized and encrypted in transit and at rest. Personally identifiable information is not required for analysis. Processing can be kept in region with data centers in the EU, US, Australia, Singapore, and Japan to support regulatory needs.

    An average enterprise receives millions of files to their Salesforce per year

    File Protection helps you close the malware blind spot

    Get a Free Demo

    THE #1 SALESFORCE MALWARE PROTECTION SOLUTION

    Fill the form and get:

    Free 15-day trial – test the product without limitations

    Real attack simulation and product demo

    Free customized and actionable risk assessment

    Cloud Protection for Salesforce

    Required field.

    Please enter a valid business email address.

    Invalid field.

    Required field.

    Enter your first and last name, separated by a space.

    Required field.

    Invalid field.

    Required field.

    Invalid field.

    Phone number can only contain numbers, spaces, and these special characters: + () -.

    Required field.

    Invalid field.

    Error sending form.

    We process the personal data you share with us in accordance with our Corporate Business Privacy Policy.

Product

  • Book a demo
  • Product
  • Solutions
  • Customers
  • Pricing

Resources

  • Blog
  • Events & webinars
  • For partners
  • Compliance
  • Datasheets
  • Risk assessment

Company

  • About us
  • W/ Elements

Support

  • Support portal
  • User guides
  • Release notes
  • Product lifecycle
  • English
    • English
    • 日本語 (Japanese)

Terms of service

Privacy

Product privacy policy

Modern slavery statement

Cookies