All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis is scoped to Einstein Trust Layer.
Salesforce sells the Einstein Trust Layer as the guardrail that makes generative AI safe for its CRM, but the masking, toxicity scoring, and audit trail it ships overlap with the controls rival guardrail platforms offer, so the technology is not what sets it apart. What comes from owning the platform rather than from writing software is the placement: the Trust Layer sits on the path between Salesforce records and external models, where regulated CRM data lives, making it a configuration step for Agentforce builders rather than a separate purchase. The public record names no customer citing the guardrail line, so its adoption tracks Agentforce. Most defensible for teams on Salesforce, weakest for a buyer comparing detection quality across model platforms.
| Description | Salesforce is a publicly traded enterprise software company whose AI CRM platform includes the Einstein Trust Layer, a set of guardrails that mask sensitive data, detect toxic output, and audit interactions between Salesforce applications and large language models. | [f1] |
|---|---|---|
| Founded | 1999 | [f2] |
| HQ | San Francisco, California, USA | [f2] |
| Latest funding | Public (NYSE: CRM), IPO 2004 | [f2] |
| Product | What it does |
|---|---|
| Einstein Trust Layer | Guardrails between Salesforce applications and LLMs that mask sensitive data, run toxicity detection on model output, log an audit trail, and enforce zero data retention with third-party LLMs. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
The Einstein Trust Layer masks sensitive data before prompts reach external LLMs, runs toxicity detection on model generations, and records an audit trail of AI interactions. These capabilities are mapped to the AI Defense Matrix. [f3]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 3/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 4/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Salesforce: Agentforce AI agent platform, Data Protection | official | 2026-06-25 |
| f2 | Wikipedia: Salesforce | press | 2026-06-25 |
| f3 | AI Defense Matrix Catalog: Einstein Trust Layer | official | 2026-06-25 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Salesforce: Trusted AI key principles “The Trust Layer includes a number of data security guardrails such as data masking, TLS in-flight encryption, and Zero Data Retention with Large Language Models.” | official | 2026-06-25 |
| s2 | Salesforce: Agentforce AI agent platform, Data Protection “The Einstein Trust Layer is a robust set of features and guardrails that protect the privacy and security of your data, improve the safety and accuracy of your AI results, and promote the responsible use of AI across the Salesforce ecosystem.” | official | 2026-06-25 |
| s3 | Salesforce Developers: Inside the Einstein Trust Layer “The Einstein toxicity detector uses a hybrid solution combining a rule-based profanity filter and an AI model developed by Salesforce Research (Transformer / Flan-T5-base model trained on 2.3 M prompts from seven legal-approved datasets).” | official | 2026-06-25 |
| s4 | Salesforce Developers: Inside the Einstein Trust Layer, audit trail “The audit trail includes timestamped metadata detailing the context of the interaction with the LLM, including the original prompt, safety scores logged during toxicity detection, and the original output from the LLM.” | official | 2026-06-25 |
| s5 | Salesforce: Agentforce pricing “Flex Credits offer the most flexibility and scalability. Conversations offer flat-pricing, while Flex Credits align cost to value. Conversations are optimized for external facing customer agents, while Flex Credits scale across any Agentforce use case.” | official | 2026-06-25 |
| s6 | Wikipedia: Salesforce “Founded by former Oracle executive Marc Benioff in March 1999, Salesforce grew quickly, making its initial public offering in 2004. For fiscal year 2026 (ending January 31, 2026), the company reported record annual revenue of $41.5 billion.” | press | 2026-06-25 |
| s7 | AI Defense Matrix Catalog: Einstein Trust Layer “Masks sensitive data such as social security numbers before prompts reach LLM providers, runs toxicity detection on LLM generations, and records an audit trail of AI interactions, with zero data retention agreements covering third-party LLM partners.” | official | 2026-06-25 |
| s8 | TechCrunch: Salesforce launches AI Cloud to bring models to the enterprise “Salesforce is touting Einstein Trust Layer, a new AI moderation and redaction service. Similar to Nvidia's NeMo Guardrails, Einstein Trust Layer attempts to prevent text-generating models from retaining sensitive data, such as customer purchase orders and phone numbers.” | press | 2026-06-25 |
| s9 | VentureBeat: Salesforce announces AI Cloud to empower enterprises with trusted generative AI “At the core of AI Cloud lies the new Einstein Trust Layer. Salesforce says that the Einstein Trust Layer aims to establish trust in enterprise generative AI by protecting sensitive data within AI applications and workflows.” | press | 2026-06-25 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Salesforce: Trusted AI key principles “The Trust Layer includes a number of data security guardrails such as data masking, TLS in-flight encryption, and Zero Data Retention with Large Language Models.” | official | 2026-06-25 |
| s2 | Salesforce: Agentforce AI agent platform, Data Protection “The Einstein Trust Layer is a robust set of features and guardrails that protect the privacy and security of your data, improve the safety and accuracy of your AI results, and promote the responsible use of AI across the Salesforce ecosystem.” | official | 2026-06-25 |
| s3 | Salesforce Developers: Inside the Einstein Trust Layer, toxicity “The Einstein toxicity detector uses a hybrid solution combining a rule-based profanity filter and an AI model developed by Salesforce Research (Transformer / Flan-T5-base model trained on 2.3 M prompts from seven legal-approved datasets).” | official | 2026-06-25 |
| s4 | Salesforce Developers: Inside the Einstein Trust Layer, audit and masking “When we identify a PII element within a prompt, we substitute it with a designated placeholder. The audit trail includes timestamped metadata detailing the context of the interaction with the LLM, including the original prompt and safety scores logged during toxicity detection.” | official | 2026-06-25 |
| s5 | Salesforce: Agentforce pricing “Flex Credits offer the most flexibility and scalability. Conversations offer flat-pricing, while Flex Credits align cost to value. Conversations are optimized for external facing customer agents, while Flex Credits scale across any Agentforce use case.” | official | 2026-06-25 |
| s6 | TechCrunch: Salesforce launches AI Cloud to bring models to the enterprise “Salesforce is touting Einstein Trust Layer, a new AI moderation and redaction service. Similar to Nvidia's NeMo Guardrails, Einstein Trust Layer attempts to prevent text-generating models from retaining sensitive data, such as customer purchase orders and phone numbers.” | press | 2026-06-25 |
| s7 | VentureBeat: Salesforce announces AI Cloud to empower enterprises with trusted generative AI “At the core of AI Cloud lies the new Einstein Trust Layer. Salesforce says that the Einstein Trust Layer aims to establish trust in enterprise generative AI by protecting sensitive data within AI applications and workflows.” | press | 2026-06-25 |
| s8 | Salesforce Developers: Inside the Einstein Trust Layer, zero retention gateway “If the prompt is sent to external models that are part of our shared trust architecture, it is encrypted in flight and the data within them is not retained by the model that it is calling. The first LLM partner that we have launched with is OpenAI.” | official | 2026-06-25 |
| s9 | arXiv: Zero Data Retention in LLM-based Enterprise AI Assistants, A Comparative Study of Market Leading Agentic AI Products “Salesforce Agentforce's zero data retention architecture foundation is its "Einstein Trust layer," a component of AI Cloud Einstein GPT that guarantees any prompt or response transmitted to an LLM is ephemerals.” | research | 2026-06-30 |
| s10 | The Hacker News: Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection “Salesforce has since re-secured the expired domain, rolled out patches that prevent output in Agentforce and Einstein AI agents from being sent to untrusted URLs by enforcing a URL allowlist mechanism.” | other | 2026-06-30 |
| s11 | U.S. SEC EDGAR: Salesforce, Inc. Form 10-K fiscal year ended January 31, 2026, Trust Layer guardrails “Our Trust Layer is built into the Platform to help customers safely use their data and set guardrails on what AI agents do with that data.” | regulatory | 2026-06-30 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.