Compliance.
All posts.
Salesforce Certificate Trust Store: Your Own Root CAs, for Named Credentials Only
Winter '27 lets you upload and manage your own root certificates in Salesforce. The scope is narrower than it first looks, and that scope is the story.
Salesforce Lets You Allowlist Chrome Extensions on Experience Cloud Sites
Winter '27 lets you allowlist specific Chrome extensions as trusted URLs on an Experience Cloud site. What it controls, and the two limits that matter.
Sending PII from Salesforce: Transport Encryption Is the Wrong Control
Encrypting the connection does not solve emailing personal information. What IPP 5 actually asks, and the pattern that keeps the data inside your control.
Sending Email from Salesforce Securely: SMTP Is Not Encrypted by Default
SMTP is cleartext by design and TLS is opportunistic. Why Preferred Verify still sends in the clear, and what to configure so email is actually protected.
Salesforce Winter '27 Security Readiness: The Release Updates and the Sandbox Window to Test Them
Winter '27 enforces two security changes, not the five widely listed. Three slipped to 2027 or were cancelled. The dates, what breaks, and how to test.
Salesforce Is Retiring the Email Change Verification Exemption: Set Up Authorized Email Domains Before 1 December 2026
Adopt Authorized Email Domains was cancelled. Its replacement enforces 1 December 2026. How to keep your email verification exception before it lands.
Salesforce Report-Export Step-Up Enforcement: The Known Issues and Gotchas Nobody Warned You About
Blocked exports, a broken Login As, and RPA jobs failing: the practitioner known issues behind Salesforce report-export step-up enforcement in July 2026.
Sizing a Salesforce Access Model: Team Shape, Internal vs External Admins, and What It Costs to Run
A full access model is not always the right one. How to size it to your team, flex it for external delivery partners, and what the whole thing costs to run.
IPP 3A Is Live: Building New Zealand's Indirect-Collection Notice into Salesforce
New Zealand's IPP 3A now requires notice when you collect personal data indirectly. Build compliance into Salesforce with source fields, a Flow, one report.
Salesforce MFA Enforcement Update: What Was Paused, What Still Applies, and the Revised 2026 Dates
Salesforce paused its all-employee MFA enforcement over a security-key enrolment bug and revised the 2026 dates. Here is what moved and what still applies.
Salesforce Data Sovereignty in New Zealand: There's No NZ Region, So What Actually Protects Your Data?
Salesforce has no New Zealand region, so your data sits offshore. What data residency, the US CLOUD Act, and NZISM actually mean for NZ gov and health orgs.
Salesforce Security Enforcement in 2026: Every Change, Date, and What Admins Must Do
Across 2026 Salesforce turns a stack of security recommendations into hard enforcement: MFA, report step-up auth, IP blocking and more. The full list and dates.
Salesforce MFA Enforcement in 2026: What Admins Must Verify and Do
Salesforce moves from contractual MFA to hard enforcement in mid-2026, with a stricter phishing-resistant bar for admins. How to verify your org and comply.
Why Salesforce Health Cloud Needs Its Own Security Review
Salesforce Health Cloud holds your most sensitive data, and the features that make it useful are the ones that expose it. What a security review checks.
Mapping Salesforce Security to NZISM, the NZ Privacy Act and ISO 27001
How to map Salesforce security findings to NZISM, the NZ Privacy Act, HISO 10029 and ISO 27001 using a source-verified, version-pinned control catalogue.