Part ofProtection and Enforcement
Salesforce Dynamic Data Masking
Protect Sensitive Data Without Changing the Salesforce Record
Mask sensitive values before they reach users, so teams can keep working with Salesforce records while reducing unnecessary exposure.
- Choose sensitive data
- Apply a masking rule
- Review masking events
The customer need
Not every Salesforce user needs to see every value
Salesforce records can contain personal, financial, credential, and other sensitive information alongside the details people need for everyday work.
DataSunrise helps teams limit what appears in everyday Salesforce use without rewriting the application or maintaining a different rule for every screen.
How it works
Protect a Salesforce response in three steps
DataSunrise checks the response as it travels to the user and applies the masking rule where protected data appears.
-
Response
Salesforce returns the requested data
The response passes through the configured DataSunrise web-application integration.
-
Policy
DataSunrise finds and masks sensitive values
An Information Type identifies matching content, and the rule replaces it with the configured mask.
-
Result
The user receives a protected response
Matching values are concealed before the response reaches the user.
Define Sensitive Data Once
Information Types tell the masking rule what to protect. Teams can use built-in definitions or create their own for personal, financial, credential, or business data.
Because the rule follows the Information Type rather than a specific Salesforce screen, the same definition can protect matching values wherever the integration can inspect them.
Review Masking Activity
DataSunrise records matching masking events. Security teams can use the event history to confirm that the policy is working, investigate recurring matches, and refine the rule when business needs change.
Frequently Asked Questions
Does masking change data stored in Salesforce?
No. Dynamic masking changes the response delivered to the user. The original record remains available in Salesforce.
How does DataSunrise know which values to mask?
The rule uses DataSunrise Information Types to identify sensitive content. Teams can choose built-in definitions or create definitions for their own data.
Is this the same as Salesforce Static Data Masking?
No. This product protects live Salesforce responses. It does not create or alter a Salesforce data copy.
Map the right workflow