Secure data retrieval & grounding
The agent only sees the CRM data the running user is allowed to see. Record-level sharing, field-level security and permission sets are enforced before anything is sent to a model.
FAQ
The Einstein Trust Layer is the security architecture that sits between your Salesforce data and the large language models that power Agentforce and Einstein. Its job is simple to state and hard to build: your customer data stays yours, stays protected, and is never used to train AI models.
When an Agentforce agent answers a question, data from your org is sent to a large language model to produce a response. The trust layer is the controlled gateway that every one of those calls passes through — there is no way to route around it.
Salesforce does not run its own models for these features. It brokers calls to trusted external models under strict contractual and technical controls, and the trust layer enforces those controls on every request and every response.
Five mechanisms work together on every single AI request. Together they mean customer data is never exposed, never stored by the model provider, and never used for training.
The agent only sees the CRM data the running user is allowed to see. Record-level sharing, field-level security and permission sets are enforced before anything is sent to a model.
Personal data — names, emails, phone numbers, national IDs — is detected and masked before the prompt leaves Salesforce, and de-masked in the response. The model never sees the real values.
Salesforce's agreements with model providers guarantee prompts and responses are not stored by the provider. Once the answer is generated, nothing remains on the model side.
Your data is never used to train or improve any AI model — not Salesforce's, not the provider's. This is a contractual guarantee, not a setting that can drift.
Responses are screened before they reach a user, and every prompt and response is logged in an audit trail you can review — important evidence for GDPR and the EU AI Act.
The most common question we hear from Nordic companies is whether their customer data will end up inside a public AI model. With the trust layer the answer is no — twice over. Technically, providers receive masked prompts under zero-retention terms. Contractually, Salesforce's Data Processing Agreement prohibits using customer data for model training.
This is also why we recommend staying inside the platform's own AI features rather than wiring CRM data directly into external model APIs, where these guarantees do not automatically apply.
We help Nordic companies map their data flows, configure the trust layer correctly and document it for DPOs and procurement. A short review usually answers most questions.
Book a trust review