How does the Einstein Trust Layer protect data during Agentforce LLM interactions?
Suggested answer
The Einstein Trust Layer is the security and governance framework that sits between Salesforce and any LLM provider. Its key protections:
1. Zero Data Retention (ZDR): Salesforce's agreements with LLM providers (including OpenAI and Anthropic) guarantee that data sent to the model is not used for training and is not retained after the response. No customer data persists outside the Salesforce trust boundary.
2. Data Masking and Anonymisation: Before sending a prompt to an external LLM, the Trust Layer scans for PII (names, emails, phone numbers, SSNs) and replaces them with anonymised tokens. The response is de-anonymised before being returned to Salesforce.
3. Toxicity Detection: Both input prompts and LLM responses are screened for harmful, offensive, or policy-violating content. Flagged content is blocked before reaching the user.
4. Audit Trail: Every LLM call — input prompt, output, model used, timestamp, and user — is logged in the Einstein Trust Layer Audit Trail, accessible to admins for compliance and investigation.
5. Grounding: The Trust Layer enforces that agents can only access Salesforce data the running user is permitted to see, via standard Salesforce sharing and FLS.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.