DataSunrise Achieves AWS Data & Analytics Competency. Learn more →

Part ofProtection and Enforcement

Salesforce Dynamic Data Masking

Protect Sensitive Data Without Changing the Salesforce Record

Mask sensitive values before they reach users, so teams can keep working with Salesforce records while reducing unnecessary exposure.

  • Choose sensitive data
  • Apply a masking rule
  • Review masking events

Not every Salesforce user needs to see every value

Salesforce records can contain personal, financial, credential, and other sensitive information alongside the details people need for everyday work.

DataSunrise helps teams limit what appears in everyday Salesforce use without rewriting the application or maintaining a different rule for every screen.

Protect a Salesforce response in three steps

DataSunrise checks the response as it travels to the user and applies the masking rule where protected data appears.

  1. Response

    Salesforce returns the requested data

    The response passes through the configured DataSunrise web-application integration.

  2. Policy

    DataSunrise finds and masks sensitive values

    An Information Type identifies matching content, and the rule replaces it with the configured mask.

  3. Result

    The user receives a protected response

    Matching values are concealed before the response reaches the user.

01

Define Sensitive Data Once

Information Types tell the masking rule what to protect. Teams can use built-in definitions or create their own for personal, financial, credential, or business data.

Because the rule follows the Information Type rather than a specific Salesforce screen, the same definition can protect matching values wherever the integration can inspect them.

02

Review Masking Activity

DataSunrise records matching masking events. Security teams can use the event history to confirm that the policy is working, investigate recurring matches, and refine the rule when business needs change.

FAQ

Frequently Asked Questions

Does masking change data stored in Salesforce?

No. Dynamic masking changes the response delivered to the user. The original record remains available in Salesforce.

How does DataSunrise know which values to mask?

The rule uses DataSunrise Information Types to identify sensitive content. Teams can choose built-in definitions or create definitions for their own data.

Is this the same as Salesforce Static Data Masking?

No. This product protects live Salesforce responses. It does not create or alter a Salesforce data copy.

See how DataSunrise works with your technology stack

View Integration Examples