Salesforce Shield and eperi sEcure take different approaches to protecting sensitive Salesforce data.
Salesforce Shield is a native security solution within the Salesforce platform. It offers features including Platform Encryption, BYOK, and Search Index Encryption. eperi sEcure, by contrast, uses Pre-Cloud Encryption: Sensitive data is protected within the organization's environment before being transmitted to the Salesforce Cloud, with full control over the keys and encryption process.
The key difference lies in where encryption takes place and who controls the data and keys.
eperi sEcure vs. Salesforce Shield at a Glance
| Criterion | eperi sEcure | Salesforce Shield |
| Native Salesforce solution | No | Yes |
| Pre-Cloud Encryption | Yes | No |
| Platform Encryption | – | Yes |
| BYOK | Customer-controlled | Yes |
| Search Index Encryption | No | Yes |
| Multi-SaaS | Yes | Salesforce-centric |
| Multi-Cloud | Yes | Salesforce-centric |
| Selective encryption | Yes | Function-dependent |
| REST/SOAP/Bulk API | Yes | Salesforce APIs |
| Search/Filter/Reporting | Functionality preserved | Functionality depends on encryption scenario |
Salesforce currently documents BYOK support for Field-Level Encryption, Event Log Data, Search Index Encryption, and Database Encryption.
How Does Salesforce Shield Work?
Salesforce Shield Platform Encryption is part of the Salesforce security architecture.
Relevant features include:
- Field-Level Encryption
- Database Encryption
- Search Index Encryption
- BYOK
- Key Management
- External Key Management or corresponding key-control options
For example, Salesforce encrypts Search Index Files using AES-256 at the segment level.
Shield is therefore much more than a simple “Encryption at Rest” feature.
How Does eperi sEcure Work for Salesforce?
eperi sEcure uses Pre-Cloud Encryption.
Sensitive information is encrypted within the protected corporate environment before it reaches Salesforce. eperi supports, among other things, search, validation, filtering, and reporting, as well as REST, SOAP, and Bulk API.
The core architectural principle:
Salesforce receives only encrypted or otherwise protected sensitive data.
The Key Difference: Where Does Encryption Take Place?
With Salesforce Shield, encryption is part of the Salesforce platform.
With eperi sEcure, encryption is positioned as an independent security layer before the cloud.
This means the comparison is not simply about two encryption algorithms, but about two different trust models.
What Does This Mean for Data Sovereignty?
Data sovereignty encompasses more than data residency.
Relevant aspects include:
- Who controls the keys?
- Who can decrypt the data?
- Where does the encryption take place?
- Which systems can see plaintext?
- How dependent is the security architecture on the cloud provider?
eperi sEcure explicitly provides customer control over encryption keys and Pre-Cloud Encryption.
Maintaining Functionality Despite Encryption
A key decision factor is the question:
Can Salesforce continue to work effectively with protected data?
Salesforce has continued to enhance its native encryption capabilities in this area. Search Index Encryption is now part of Shield and protects Salesforce search indexes.
eperi lists the following capabilities for its solution, among others:
- Search
- Filtering
- Validation and deduplication rules
- Reporting
- REST API
- SOAP API
- Bulk API
- Mobile Apps
- Third-party tools (e.g., via REST)
When Is Salesforce Shield the Right Choice?
Shield is particularly relevant for organizations that:
- are looking for a deeply integrated Salesforce security solution,
- want to use Salesforce-native encryption,
- require BYOK,
- want to manage their Salesforce security architecture within the platform,
- are willing to trust Salesforce with their plaintext data.
When Is eperi sEcure Relevant?
eperi is particularly relevant when:
- data should be protected before entering the cloud,
- Salesforce is not the only cloud application,
- an independent security layer is desired,
- multi-SaaS or multi-cloud is relevant,
- sensitive data should not leave the organization's environment in plaintext.
Salesforce Shield and eperi sEcure address related, but not identical, challenges.
Shield provides deeply integrated native Salesforce encryption. eperi sEcure introduces an additional or alternative architectural layer: protection before the cloud and control over data independently of the underlying SaaS platform.
The right choice therefore depends on whether the primary focus is native Salesforce security or platform-independent data sovereignty.
FAQ
What is the difference between eperi and Salesforce Shield?
Shield is integrated into Salesforce; eperi sEcure follows an independent Pre-Cloud Encryption approach.
Does Salesforce Shield support BYOK?
Yes. Salesforce documents BYOK for several Shield encryption capabilities.
Does eperi encrypt Salesforce data before it reaches the cloud?
Yes. This is a core component of eperi's solution for Salesforce.
Is Salesforce Shield sufficient for data sovereignty?
This depends on the definition and level of the sovereignty requirements. Salesforce Shield provides extensive native capabilities for encryption, key management, monitoring, and compliance. However, data sovereignty encompasses considerably more than encryption and key control.
A comprehensive assessment should consider at least the following aspects: jurisdiction, ownership and control, operational control, administrator access, key control, metadata, support access, subprocessors, legal compulsion, and the physical location where data is stored and processed.
As a cloud provider, Salesforce continues to retain certain elements of technical and operational control over the platform. Depending on the level of sovereignty required, Shield alone may therefore not be sufficient to ensure complete data sovereignty. Organizations that specifically want to technically prevent cloud provider, administrator, support, or legally compelled access to sensitive data can use an additional architecture such as eperi sEcure, in which sensitive data is encrypted or tokenized before it enters the Salesforce Cloud.
Want to use the cloud without giving up control over your data?
Learn how eperi sEcure protects sensitive data in SaaS and cloud applications.
Newsletter
Sign up for our newsletter and receive regular updates on data protection topics, changes in legislation and the further development of eperi® sEcure.
