Salesforce, Inc. (CRM) Earnings Call Transcript & Summary
January 16, 2025
Earnings Call Speaker Segments
Moya McKay
executiveHello, everyone, and welcome to today's Salesforce session. Thank you all for joining us today. We see we have a lot of people in the room who are excited. So before I begin, I want to cover a few quick notes about our webinar platform. Today's webinar will be available on demand after we wrap up. It will be accessible through the URL you are on right now, and will also be sent to you via e-mail tomorrow. So please keep an eye out for an e-mail with a link to watch today's presentation on demand. Please note the slides will also advance automatically throughout the presentation. If you need to enlarge the slides area or any other widget on your screen, simply drag the bottom right corner to resize. If you need technical assistance, please click on Help Widget located on the bottom left corner of your console. We've also added some additional resources, which are available through the resources library to the right of the slide. There, you can find additional content, including white papers, webinars, e-books, trailheads and so much more in addition to a few sessions for our Dreamforce that's coming up this week. [Operator Instructions] Lastly, let us know what you think of today's presentation by sharing your feedback via our webinar survey. We also welcome you to share your excitement in the moment using the emoji reactions available on your screen. Lots of you are already using them, and our speakers can see them. So feel free to use the thumbs up, smiley face, celebration and heart emoji reactions, to let them know what you love most about today's presentation. So with that, I'm going to hand it over to Kirstin to kick us off. Kirstin, over to you.
Kirstin Meyerhoeffer
executiveAll right. Thanks for that intro, Moya. Loving all of the emoji reactions, everyone. So thank you for that -- those signs, we're getting them. Thanks for joining us today for our webinar. We're going to go deep into the security road map. I'm specifically talking about what's on the docket for Shield and Security Center. So let's go ahead and jump right in. So in true Salesforce fashion, I want to start by thanking you all, and not only for taking the time to join us today and to tune in but also for being our customers, our partners and ultimately, our trailblazers. As many of you know, Salesforce would not be anything that it is and it embodies without you. And the road map items that we're about to discuss would certainly not be what they are without you. So thank you so much. We greatly appreciate your partnership and your feedback. Everyone's favorite slide. Just a quick reminder. The -- what we'll talk about today, a lot of it is forward-looking. Salesforce is a publicly traded company, so just base your purchasing decisions on products and services that are currently available. All right. And I'm Kirstin Meyerhoeffer. I am a Senior Product Marketing Manager focusing on the Shield portfolio based out of Sunny, Denver. I'm joined today by Pete Thurston, an invaluable leader of the Data Security Product portfolio here at Salesforce. Pete, it's great to have you. I think this is our first webinar together. I'm really -- I'm excited to be here with you.
Pete Thurston
executiveYes. We hang out all the time, but nobody in the real world knows that. So yes, I'm also in Sunny but San Diego not Denver. And thanks for coming, everybody. Special thank you, by the way, referencing the thank you slide for caring about this topic. It's very near and dear to our hearts, and we're really, really excited to see how many people have decided to join us today. So thanks for coming.
Kirstin Meyerhoeffer
executiveAwesome. Echoing those sentiments. All right. So we know that you all -- every organization, you want to build fast, you want to take advantage of all of the awesome technology that's at your fingertips, talk about all of the innovation that's come this year alone but also thinking about the future. And there's a lot of pressure to do so. You're facing a lot of pressure. I'm sure that many of you feel that from a variety of sources day in and out, notably from your customers and their expectations. And this is a challenge. There are a number of challenges that arise with this, a variety of reasons. First of all, it's really hard to build fast if you don't have the right tools. Secondly, when you're building fast, you're moving and deploying really quickly, really swiftly. That's accompanied by some really serious security risks and challenges of their own. So as you look across your business, there are a few factors that you might be seeing. First of all, disparate systems. That's huge when you're collecting more data than you may have ever done so before. And then when you think about the influx of technology, notably generative AI, it's at the top of all of our minds, we can admit it, there are a lot of new, more creative threats that are coming to the forefront. So the way I kind of think about it sometimes for all of you, Ted Lasso fans out there, there's a wider goal. It might even be a little differently shaped, and our goalie might not yet have the full reach or the full span to ensure full coverage with these new threats that are coming to the forefront. And ultimately, these potential gaps are ones that your customers are thinking about. In a recent poll, over half of consumers expressed that they don't feel the AI is secure. So thinking about these increased security threats, those can cause business downtime, which is difficult on its own. We don't want any sub-1s, sub-0s, let alone when you're juggling compliance and regulation requirements as well. And in addition to that, you've got to make sure that your system is foolproof. You've got to make sure that neither you or your team is leaving a metaphorical key under the mat. You're probably a great person, what the heck does that mean? So this is a metaphor that what we often use when we talk about the shared trust model and shared responsibility model, rather that we have with you all with our customers. Trust is obviously our #1 value here at Salesforce. Most of you are intimately familiar with that. And you can implement a state-of-the-art security system, which is exactly where we come in. We give you the infrared technology, the top-notch window locks, the advanced cameras. But if you leave a spare key under the mat, maybe that's for convenience, maybe that's because you're letting a neighbor in for a favor, you ultimately increase the risk that someone might break in, right? And in doing so, you also increase your risk exposure. So when we think about that and when we think about other factors to keep in mind, in parallel with that, there are increasing threats that are on the rise, we kind of talked about that earlier. And those are impacting your customer data. They're also impacting customer trust. And so when you are bringing together all of this critical customer data, you've got more data than ever before, it's crucial to think about how you're securing and protecting it and ultimately, the impact on your customers' trust and of your brand. It's also really critical to think about the laws and the regulations, the policies that governments and industry-specific bodies have issued or in the process of issuing to protect that customer data. And sometimes, it's really hard to keep up with all of these regulations, they're changing, they're evolving, there are new ones. We actually have a new regulation, white paper out that even focuses on some of the new AI-specific regulations that are coming to the forefront. And so you kind of think about those things, balance those things, and data security attacks are also becoming more sophisticated. Thinking about that and how tech leaders are responding, over half of tech leaders have indicated that they're introducing enhanced security measures as a result of that. And then you've got to think about some of these staggering stats like the fact that it takes over 3/4 of a year to identify and contain a security breach and that the cost of that is quite expensive. It's more expensive than ever, actually. It's an all-time high as of last year and it jumped to about $4.5 million on average, which is over 15% more than in 2020. So that's why we've built a suite of products that provide you with trusted security, privacy and compliance for your Salesforce data and that ultimately help you minimize risk, address regulatory concerns and also avoid permanent data loss. So at a high level, think about if you're building a custom app on the Salesforce platform and you want to ensure proper security protocols are introduced, built right in. Salesforce Shield and Security Center, it's going to be the focus of our topic today, spoiler alert. They allow you to do that. Also thinking about some of our other products in the mix. You might want to ensure that the data that you're handling across each of your Salesforce orgs helps with HIPAA, for example or maybe another regulation. For that, products like Security -- or Privacy Center, Security Center as well and also Data Mask, can help you in that compliance journey. And then also thinking about backup, archival and storage, for those protocols, Salesforce Backup, Salesforce Archive and Hyperforce are incredibly useful. So this whole platform portfolio of products has helped our customers reduce costs, IT cost specifically by an average of 27% and reduce data breaches by an average of 30%, which is pretty impressive. So thinking about securing your enterprise, we like to do so and think about those products that we were kind of just talking about in a 3-step framework. You can kind of see that, this has a flywheel affect. It's always on. So understanding your data, protecting your data and monitoring your data. And the reason that this is always on is that it's meant to maintain the most up-to-date and efficient security practices for your organization. Unfortunately, I think we all know with security, you can't just like set it and forget it. You have to continue to analyze and ensure that your systems and your protocols are working as you intended to and as they should. So depending on where you are in your data security strategy and what your company's unique needs are, you might, a, be familiar with some of these products and/or b, made of a different variety or the combination of them. But in short and looking at this full wheel, all of these products were built in response to a lot of feedback from you. So customer requests for off-the-shelf, really easy to implement products, and those that ultimately ensure that your data is protected and that you're delivering seamless and secure experiences to your own customers. So we've got that full wheel, let's zoom in on what we're talking about today. We're going to talk about this subset of products. Many of you are most likely familiar with them. Shield. It's a bundle of 4 products. We'll go into an overview of what those are in just a second, and Security Center. And so thinking about what's on the docket for us today, we're going to talk about the core components of these products, key use cases, recent innovations that have been delivered already, and then we're going to go deep into the goodness that's coming. So first, let's go ahead and start with Shield. So Shield, I love Shield, I'm biased, but I love Shield. Think about it as introducing a really comprehensive data security plan for your critical data in Salesforce. It's a suite of products. It primarily exists for many of you who need that extra layer of added protection and security that goes above and beyond the security that's baked into the platform for all of our customers. So some use cases to think about. You might be an organization who needs to meet compliance or industry regulatory requirements. You might need to monitor and have added abilities to monitor access to sensitive information that's stored in Salesforce or maybe you need to just ensure that your implementation is working, that your implementation is optimized for high scale, that it's efficient for your business, especially those of you in larger and more complex organizations. Salesforce Shield can help with all of these things, which is great. And it includes 4 key services: Event Monitoring, Field Audit Trail, Platform Encryption and Data Detect. So let's go ahead and take a closer look at what each of those products do at a high level. So with Event Monitoring, you can gain this really rich access to detailed performance, security usage data on all of your Salesforce apps and that allows you to really monitor that critical business data across Salesforce to understand user adoption, who is adopting these new apps that you've created the features within the apps, how are they interacting with the UI, and you can also troubleshoot and optimize application performance. We kind of talked about that on the previous slide. A really cool aspect of Event Monitoring that I love is that you can build flexible, customizable security policies called transaction security policies and that gives IT the ability to identify and prevent malicious activity in real time. Think back to some of the newer AI threats, quishing is a new term, QR codes and using QR codes to get access into environments and take critical data. So thinking about some of those things, Event Monitoring is critical for this. Field Audit Trail allows you to retain data history for really forensic-level compliance and so that you can grab and snag greater operational insights into your business. Taking it to number three, platform encryption, pretty straightforward, but you can natively encrypt your most sensitive data, especially for those of you who are in highly regulated industries while retaining critical app functionality. And then Data Detect, with this, this is a really neat add-on to the bundle or this overarching solution. Customers can quickly find sensitive data that might not have even been visible or known within the org. Think about maybe a social security number that you didn't know existed in the text field. With Data Detect, you can identify that information and then take action to classify or reclassify it according to your security policies. All right. So we've covered Shield. Let's also talk about Security Center. I also got some mad love for Security Center. So think of it as kind of the center of the universe for all things security related in Salesforce, kind of like your control pad. It simplifies the management of security across your entire Salesforce rollout and that allows users to really gain a solid understanding of their overarching security posture, and as an IT leader, for example, your overarching stance on your security posture. You can also gather some really rich key insights to improve that posture where necessary. So with Security Center, you can collect over 60 key user permission and org configuration metrics. And then it consolidates these metrics into a single view that's easy to review, it's clear and you get that sense of how your security posture is performing, what it looks like across your entire Salesforce environment. You can also -- and we'll get into some of this later, create alerts on these metrics, and you can be proactively notified when your security posture changes and create security policies to configure key security settings once and then deploy across your orgs. Last thing I'll mention here is that Security Center also works with other security products that we'll talk about today, namely event monitoring. It also works with other products like mobile app security and health check to provide a really that nice bird's eye singular view of all of your settings across your orgs. All right. A lot of information, but let's dive in. Let's talk about the releases that we've recently deployed as well as what's on the docket. Pete, I'm going to pass it over to you. Take it away, my friend.
Pete Thurston
executiveRight on. Well, thank you very much, Kirstin. The first thing, everybody is here because this is a road map session, right? So you get to the road map. But I would not be a very good product person if I didn't brag about all the cool stuff we've already done. And then I promise you there's plenty coming your way for road map any minute here. So let's do a quick look back at the last few releases. Just -- there might be some things here that if you didn't read all of our release notes, I know everybody does, but if you didn't, I've got some highlights for you here. So let's take a look at some of these things. So looking back to Winter '24, let's talk a little bit about what we did here. And just to kind of lay the way this works out, there's a lot of products here, guys. So we're going to run through them. You'll see some color coding, assuming you're not color blind and we'll walk through them that way. So starting with Winter '24, you're going to notice some themes throughout this. But in Winter '24 with Event Monitoring, we were really excited to be able to finally pilot Event Log Objects. We're going to talk a lot about Event Log Objects here today. But if you're part of the pilot, you already know how great they are, and I got some really exciting news for you about them today. And with platform encryption, you'll also notice a pilot in there. And what you're going to see is a couple of themes that go through a bunch of stuff here. You'll notice something you may not have seen before is called Database Encryption, but you've probably heard about it if you're on this call. It's the artist formerly known as tenant-level encryption or TLE. It now has an official fancy name and that official fancy name is Database Encryption. So we are very excited about what we did in that release. And then we just kind of kept going, and we said, let's do some more of that. Event Log Objects is a big, huge area. We're going to a lot of detailed slides on this in a minute. But the pilot has lasted a couple of releases already, and we've learned a ton from the people who have been using it. So we -- but we can't just do the new cool, hot stuff that's coming down the pipe, we also keep adding new events. And so we added in a new guest user anomaly threat detection type in Spring '24 that can help with customers securing their Experience Cloud as well as Lightning Logger, which is one of -- which is actually the first custom monitoring logging library we've made available to our customers to write directly into the Event Monitoring pipeline. So Lightning Logger is GA now. It will allow you to instrument your custom Lightning components so that you can get that right alongside all the cool stuff we do with your standard components. Another big thing that we were able to do in Spring '24 on the encryption side is external key management. So if -- for customers who have leveraged platform encryption in the past, wanted to use BYOK, but really wish they could actually have even more control and keep the keys outside of the system, the only option we used to have for you was Cache-Only Keys. With Spring '24, though, we were able to go GA with external key management for AWS. So if you use AWS as your key management as a service provider, you can directly attach those external keys to our platform encryption service, and we'll just use those instead. So we've made that whole process a lot, lot easier. And like I said, we're building a lot of cool stuff, but there's still the existing stuff that we need to ensure those foundations are strong. So we added support for even more standard fields in Spring '24 for encryption, including things that come back from Gen AI. So very exciting. And actually, there's one other big thing that we'll talk about here on the -- sorry, keys don't work. Okay. On the Summer '24, you'll see these themes keep going with Event Log objects going from pilot to beta, which is really, really exciting. We got even more eyeballs on the product and the offering is really shaping up to be super strong. But we made a huge announcement in Summer '24, where we expanded event log file retention. So one of the biggest things we have wanted for ourselves as well as our customers for a very long time is to be able to store event log files for longer than 30 days. Well, with Summer '24, we updated that. And all of our event log customers, all of our Event Monitoring customers can now enjoy retention on the platform for up to a year. You do have to turn this on. So if you're a current Event Monitoring customer, you just -- it's a one check box, but you do need to go check that check box. So see the release notes or follow up and we can get you those. But very, very excited about that. And with Summer 24, the other big thing we did was there's something called the ELF Browser, which has been a loved, little app that's been out on Heroku for a very long time, but not officially supported. We brought that into the setup menu. So for event monitoring customers, you can now interact with your event log files directly within the platform without having to jump out to a not formally supported external app. So big, big stuff. And then the green box doesn't show up a lot lately, but we're really excited that we were able to do some Field Audit Trail enhancements too in Summer '24. And really, these are pretty huge. So for our net zero cloud customers, being able to know what's happened in the past is absolutely essential. And we added more objects and fields as supported for Field Audit Trail in that release than currently existed for pretty much anything. So we're really, really excited that we enabled all those Field Audit Trail objects for Net Zero cloud. And when we did that, we're like, wow, this is a lot to manage. So we actually went ahead and rolled out a new setup UI to manage field history tracking across all of your objects centrally within the setup interface for Field Audit Trail customers. So really, really like that's a lot of stuff. We also did a lot of stuff with Security Center. So Security Center has had a great year. And what you're going to see is, again, themes, right? So you're going to see we consistently roll out new metrics. But what that also is going to lead to is do we have to roll out all of the metrics? Or is there stuff that customers want that maybe they can just add their own? And so what you'll see is we kept adding all these metrics and we kept improving the UI. And then we went, well, why we can -- we're going to keep doing this. We'll keep adding new standard metrics, but there's customers who want very specific things. So in Summer '24, you see there was a beta for Custom Metrics. And Custom Metrics are exactly what they sound like. They're the ability for our customers and our partners to go ahead and add their own metrics directly into Security Center with the full support of our data retention and our alerting policies and all the things that you can layer on top of them. And we've continued to make pretty large improvements in our user interface, and we will continue to do that to continue down the path of really trying to make sure that our products are surprisingly fun to use and are engaging because that makes you want to apply your security posture in a way that's going to level up for your end customers and for yourselves. So it's a big priority for us, and we've made a lot of progress this year. But okay, the drum roll moment everybody's been waiting for, let's talk about where we're going next. And this stuff is really, really exciting, although I'm still super, super, super proud of what we already did. Okay. I wanted to share with you all the way we think about our road map before we jump into the actual specifics. And I think this is really important because I think -- if we're thinking about this wrong, that's something we need to know too because these are the things we think through when we talk about what to prioritize. It all starts with enabling awareness. If you don't know what's going on, it's very hard to make good decisions about what you should be doing with your security posture. But also just giving you data isn't quite enough. We really want the products to be able to drive those aha moments for you to be like, "Oh, that's very interesting. This is something I should think about that I didn't need to really do all on my own". But once we give you that information and we give you those insights, you need to be able to do something about it. And we're trying to simplify that as much as we can too. And that's where that Empower Actions piece comes in. And finally, you shouldn't have to -- I mean, we love it when you do, but you shouldn't have to read all of the release notes all of the time to have any idea of what's available. So we try to allow our products to help inform that as they go. Okay. So where are we going? We'll take this in chunks. We're going to take this kind of product area by product area, and we're going to start off with Event Monitoring. Just a quick reminder. We already talked about Event Monitoring high level earlier, but Event Monitoring exists to help you understand what's going on in your Salesforce environment from an end user perspective. So what are the end users of the applications that you're building? What are they doing when they're in the system? This has a lot of really interesting use cases that are not just security related, right? So when we think about it, yes, event monitoring is super helpful for security use cases like being able to monitor what people are doing for compliance purposes and governance and things like that, has a lot of data loss prevention use cases. Kirstin mentioned earlier about transaction security policies being able to block data from leaving the system actively with -- instead of passively. But there's a ton of stuff in here for productivity and adoption and performance monitoring and really understanding that the things you're building are the right things for the business and are moving the needle at a business layer as well. So I think most of you probably already knew that. So let's talk about where we're going. So Winter '25, just to level set across the board here. Winter '25 is the release that's rolling out right around Dreamforce this year. So those are our kind of big Dreamforce announcement things that you'll see. And then Spring '25 is what we're hoping to ship in February of the coming year, which is not as far away as it sounds like, I'm afraid. But so Winter '25, Event Log Objects continuing in beta. We're learning a lot. We're rolling it out to a lot more customers right now. So that beta, you'll check the release notes, you'll see how to get involved with it. We are also doing a lot of work with this little thing called Data Cloud that you might have heard about. So a lot of our customers really want to be able to leverage the power of Data Cloud to interact with large amounts of data. Well, guess what, Event Monitoring is a very large amount of data. So we have listened and we are working on making a pilot available in Winter '25 this coming month for a real-time events connector in Data Cloud. So you can get your real-time events visible in Data Cloud and use all your data cloudy goodness to analyze them and inspect what's going on with real-time events. One of the other biggest things that has been asked for forever since we launched threat detection has been, how do I test that? How do I know that when a threat detection event fires, I want to take action on it because the threat detection event is going to be a machine learning-enabled capability that says, "Hey, there's some weird behavior going on here. You should do something about that." And so people have built these really robust systems to act on them, but they can't test them. Well, we're changing that. So with Winter '25, it will be in beta where you can generate test events for threat detection types. And then looking to Spring '25, we hope to go GA with that assuming no surprises, of course. And we are targeting general availability of Event Log Objects to all event monitoring customers in Spring '25. Everybody who's sitting around going, what's Event Log objects, hang on a second. We'll get to the next slide. But -- and then obviously, our real-time events connector is going to keep going further. We're also working on even more data cloud integrations that you'll see in that And Beyond column, including Event Log Objects going into Data Cloud. And we are really, really pumped on the work we're doing with distributed tracing right now. So it's already on here, even though we don't have anything for you to kick the tires on yet, but our distributed tracing work with open telemetry standards is coming along, and we're very excited to get some customer hands on it within the next few releases. Okay. So what are Event Log Objects, Pete? Great question. I'm glad you asked. Event Log Objects is something that I personally am incredibly excited about. Event Log Objects are a vastly improved experience to interact with event log data. So a little history lesson on event monitoring. It all started with event log files about 10, 11 years ago. And we generate CSV files and there are a massive amount of data, and they tell you what things have happened in your org, and that's super, super useful for a lot of our customers. But then customers were like, well, okay, once a day is great, but I kind of need something a little more frequent. And we said, okay, well, how about this? We'll give you the files hourly. And people were like, "Oh, my God, thank you so much, but can you do better?" And so it's just been this constant push, right, which is the right thing to do, is to get this data into your hands as fast as possible and make it as easy to use as possible. Event Log Objects is the answer here. So we currently have the latency to 10 minutes or less for availability of event log information. And the thing is that last word matters. So event log files are files. Event Log Objects are exactly what they sound like. They are objects on the platform that you can build platform tools on top of, you can leverage in platform familiar ways. You can run SOQL against them; you can run complex aggregates; you can filter with your SOQL; you can have vastly improved experiences in CRM analytics, which you'll actually see on this next slide, where instead of having to rely on the data processing pipelines that we ship with the current CRM analytics application, all of the Event Log Objects are directly connected to CRM Analytics. So you can run live queries from CRMA directly against these objects in seconds instead of having to work on very complex data transformation logic. So super, super excited about Event Log Objects. I cannot tell you how excited I am. Before I came to Salesforce, I was a customer and a partner, and I've been wanting this forever. So very excited to bring it to market. Next thing up, next like spotlight on Event Monitoring is that real-time events connector that I talked about. This is, again, exactly what it sounds like. So we're trying to name things based on what they do now. You're welcome. In Data Cloud, you'll be able to have a native connector for real-time events to pull that data directly into Data Cloud. That pilot is going live very, very soon here. Hopefully, we'll get great feedback and be able to promote that up to GA as fast as humanly possible. And that's the Event Monitoring double-click that I had for you. We're going to move on now to Platform Encryption. So with platform encryption, again, just a quick reminder, platform encryption is known and loved by a whole lot of people. It is our solution for encryption of data at rest on the platform. Encryption of data in transit is included across the entire platform. Data at rest is a slightly more complicated topic and not necessarily needed by everybody. So platform encryption allows that. A lot of the key things that you see on this slide here are things that we've really focused on for encryption -- for Platform Encryption specifically is how can we enable this while making sure that the system still operates as efficiently and effectively as possible. How do we make sure that customers can choose how they want to control the key material that drives that encryption and where it comes from? And ultimately allow you to build more on the platform with the confidence that you need to know that you're doing the right thing for the data. So primary use cases are really those things, right? So making sure that you have key control, making sure that if you've got contractual commitments that say you have key control, you can meet those and several regulations reference encryption control and help with that. But let's jump into where we're going because there's 2 really, really big themes here that you're going to see. I talked about database encryption earlier. I talked about how it's been a journey, and it really has. It's been a journey. The team has been working on this for quite a number of years. Database encryption, the artist formerly known as TLE or tenant level encryption, is database tier encryption for all of your data stored in the database all at once. It has none of the trade-offs that come with field-level encryption that we make available today, and we are super excited to roll this out to a beta in Winter '25, and we have high levels of confidence in a GA in Spring '25 for all of our Shield customers on Hyperforce. So there is a little bit of an asterisk there in that the technology underlying Hyperforce is what makes this possible. And therefore, this will only apply to customers on Hyperforce who have Shield. We are also really excited with Winter '25 in this next couple of weeks to be rolling out Platform Encryption for data cloud. So customers who have Shield and have always had their data encrypted in our databases based on their specific needs and are now using Data Cloud are like, okay, cool. So where is the button for that? And we're like, oh, we don't have that button yet. But the button is coming in Winter '25, and it makes it very easy to do that database-level encryption for your data cloud information right alongside everything else. So you go to the exact same place in the setup menu that you do to do Platform Encryption, for everything else, you're just going to have a data cloud option now, too. So the asterisk on that one is you do need to talk to your account team. Due to the way Data Cloud is a new technology and new pricing model for Salesforce, the price isn't different for Platform Encryption for Data Cloud than it is for existing Platform Encryption, but you do need one additional thing on your contract to help be able to drive that and make it available. So talk to your account team in about a week or 2 when we officially roll out Winter '25. Okay. So super excited there. We are working on new BYOK options for search indexes. We are working on external key management that I talked about earlier for Data Cloud. We're working on additional key providers for external key management, including Thales. And we're working on encrypting even more data stores. So lots coming down the pipe. Here's the details on database encryption. I already mentioned Hyperforce customers, beta Winter '25, but the key is it just makes this so much easier to encrypt your data within Salesforce. So again, another thing I'm incredibly excited about. We do get a lot of questions about, is this a replacement for existing platform encryption or field-level encryption? And the answer is no. It works in conjunction with existing encryption options and is an additional layer of protection for our Shield customers. So it's not -- field-level encryption is not going anywhere. Database encryption is just another layer to help you sleep safely at night. Okay. On the Data Cloud front, again, I already talked about this, but it's right next to everything else. So this is a preview of what the screen looks like. You can jump in there. It's right next door to the platform and you just enable it and everything is off to the races. Okay. So let's -- that's right, sorry, we have a demo. I forgot. So look how easy that is. You go in there and you click a button and then you click another button and you're done. That's it. It's one check box, and we will go ahead and generate the keys for you on the back end, makes life a lot easier. Okay. So back to the next product, so Data Detect. So Kirstin mentioned this earlier. Data Detect is the newest member of the Shield suite. It's the newest delivered member of the family. We really love the idea of Data Detect. So the whole purpose of Data Detect is to discover sensitive information that you might not even know that you have. That's its mission in life. That's why it exists. Primarily, it's for just knowing what you got, being able to apply the right controls to it and getting everything tightened up based on the actual data you have. I'm kind of famous for being annoying for saying, if you don't know what data you have, you don't know how you feel about it, so you don't know how you want to protect it. This helps you answer that question. Now we've learned a lot since Data Detect went GA a couple of years ago. We learned a lot that people want more patterns that people want to be able to scan more information. They want to be able to review more results that come back from those detect jobs. So we are -- we've been really, really hard at work this year on a new version of Data Detect that's going to help with all that stuff. We're calling it Enhanced Sensitive Data Detection, but really, it's just going to keep being called Data Detect. It's just that we are going to be able to help with all those things that I just talked about. We're going to be able to find and classify sensitive information across even more data but also more patterns. In fact, since we created this slide yesterday, it's out of date. I didn't get a chance to tell you, Kirstin, I found out this morning the expanded patterns that it currently says 14 on this slide, it's actually 25 patterns. We got some great new updates over the night. So we're really, really excited. People are going to be able to review a lot more data and get all of the results back and be able to take action on them. So super pumped. Pilot in Spring '25. This is a major undertaking by the team. And this is also -- do we have a demo on this one, Kirstin? I can't remember. Yes. Okay. Can we pop that up? So this is what the new UI is going to look like, what it's going to feel like. We're super pumped about this and the future. So as we go past this initial version that's going to be the 25 patterns and all the records and all the good stuff, we are actually looking to integrate AI into this solution and get even better and more fine-tuned about the way we identify sensitive information with full context of the surrounding information, not just the patterns that we are looking for. However, we are going to make massive, massive improvements with this version that's going to be piloted in spring '25. Okay. Let's switch back over the slides really quick. We got -- I thought we were going to have way too much time here. We do not have way too much time. So I'm talking as fast as I can, I promise. Okay. We're just doing a lot of stuff. It's very exciting. Okay. Security Center. Let's jump into Security Center. Kirstin highlighted this earlier, Security Center is the center of the universe for security posture management at Salesforce. It's where we pull it all together. The point of Security Center is we give you all these controls we just talked about, but how do we just make this easy to pull together and really know what's going on? There are a few key use cases that people come to Security Center with. The principle of least privilege is an obvious one for us. Security Center surfaces almost all of the very -- well, all of the really critical issues that come to do with like overpermissioning users, and it can pull it all together. We also allow you -- this is -- the org monitoring is interesting because Security Center is the only GA product that is natively multi-org. So if you've got more than one org and if you have one sandbox, you have more than one org, you can connect them all together and you can actually monitor all of your Salesforce security posture from one place. But we don't want you to have to come into the app all the time just to stare at it and be like did anything change? So you can actually set up custom alerts that will tell you when things change based on your concerns. And if you are managing multiple orgs and you want to do things like define your password policy once and ship it out to all orgs at once without having to log into them all, you can do that with Security Center and you can monitor it all centrally. That's what Security Center does. Themes, more metrics, of course, always more metrics, right? So we're adding in new things from Event Monitoring. We're adding in even more user permissions. We've got data cloud permissions already included, but we're looking for some more of those that are coming down the pipe. And one of the biggest things here is that Custom Metrics are going GA in Winter '25, so right around Dreamforce time. We're super, super pumped. I'm going to talk a little bit more about that in a second on the next slide. But we're continuing to improve the UI. I talked about that earlier, but it's just -- it keeps going, and we're just trying to make this thing as smooth as possible for everybody. And as we go forward, we're working on making that more customizable so that when you come into the app, you can tweak it to make sure your top priority things are at the top of the screen, things like that. We're going to offer more security policies, and threat detection just keeps going. So it will keep showing up in Security center the same way it does in your orgs today, but just with more threats being detected automatically for you. Okay. So Custom Metrics. This is a big topic. And what you see on the screen here is just like a few ideas we threw out, right? So what if you wanted to track Sandbox life cycle? You can do that. In fact, I did it. I was really -- that was my test use case when I was testing Custom Metrics, and it was really exciting. But what if you want to know other things? Like what if you already use partner applications to do things in the security ecosystem and you just want to pull that together with all the stuff that we already provide to you with Security Center? Well, great news. You can do that. And our partners can, too. And we actually have 2 partners who are launching Custom Metrics integrations at Dreamforce next week, come say hi. But Sonar and DigitSec are both launching custom metrics integrations next week at Dreamforce with Security Center. So if you're already a customer of DigitSec, or of sonar, you'll be able to plug the information and insights that you get from those tools directly into Security Center. So really excited about that. And if you need to know any more about that, again, see you next week, and we'll talk about it. Do we have a demo of this, Kirstin? Yes, we do. Look at that. So it's super simple. Within the application, you go straight to the new Custom Metrics tab. You define what information you want to show. Once you've got that information loaded in, it's just going to show up alongside everything else in your dashboard, and you'll be able to see it right there. We're working on some minor improvements to the UI in the current release that will be things like iconography and stuff. But all of the things that you expect from a standard metric, you can get with a Custom Metric, including alerts and all the other good stuff. Okay. Holy Cow, Kirstin, talk fast. It's all you, sister.
Kirstin Meyerhoeffer
executiveThere's a lot -- I know we got to maximize time for Q&A. We got some good questions going in. So let's just briefly recap all the goodness that we just saw. A lot of credit to the PMs, the product managers who are delivering on these things. There's a lot of good stuff coming. So let's go real fast. Things that I also am personally excited about stuck out to me. So we've got event log objects coming in beta about this time. We'll see some of that at Dreamforce for those of you who are attending. Really excited as well about the real-time Events Connector for Data Cloud pilot and Event Monitoring. And on the platform encryption front, we've got database encryption for Hyperforce, and we've also got -- and that's in beta. We also got Platform Encryption for Data Cloud, reminder to chat with someone on your account team to ensure that's set up. Looking ahead at spring, Event log Objects goes GA. We have that real-time events connector for Data Cloud going beta. So continuing to just push and deliver across each of these products. There's some really cool things that Pete just talked about in terms of the enhanced sensitive data detection. I love that we got to 25 different patterns within Data Detect. And then you'll see some patterns like database encryption for Hyperforce going GA for platform encryption in the spring. Like Pete said, it will be here before you know it. Then looking ahead to 2025, this kind of beyond column, really neat things, more integrations with Data Cloud for Event Monitoring, really across the whole portfolio. The AI-powered detection piece coming into Data Detect, really excited for that. And then some highlights on Platform Encryption, external key management for Data Cloud for Thales, we've got a lot of cool stuff coming. Quick review as well of Security Center. So metrics is the name of the game here. We got Custom Metrics going GA at, well, Dreamforce time again. Who is thinking of Dreamforce, not me. Thinking ahead to spring, more metrics, calling out some of the triggered transaction security policy events. And then looking ahead to 2025, we've got the addition of metrics, of course, some expanded security policies and the additional threat detection event types, which is awesome. Okay. Really fast before we get to Q&A, I don't think I've said Dreamforce enough during this presentation. So please come see us if you're going to be there. We're actually going to go deeper, well, we're going to go as deep, if not deeper in a session at Dreamforce. There's a bunch of other great content. You can check out this QR code that essentially has 3 perfect days that have been built out for you of great content to just come and let soak it in, soak it up like a sponge. You can also join us on Salesforce+ for many of these sessions if you're not attending live. And then if you want to continue your learning journeys for both Shield and Security Center, you've got those trails here for you. Just a reminder, I think someone did post this as a question. This deck will be shared as well the recording. And then -- or the recording specifically. Let's take it to Q&A. So I know Moya is going to come back in and help us with some of this. But with the time we've got left, let's go ahead and take some questions.
Pete Thurston
executiveWe got some good ones in here.
Kirstin Meyerhoeffer
executiveWe got some really good ones.
Moya McKay
executiveYou guys have a lot of great questions. So we're going to go ahead and jump right in. And just a reminder to everyone that if we do not get a chance to answer your question today, we will be sure to follow up with you offline. So do not worry if we don't answer your question on the call, we're going to get it answered.
Moya McKay
executiveSo first and foremost, we had a few folks asking, if you could kind of tell us a little bit more in terms of explaining custom matrixes again. Would you be able to kind of dive a little bit into just explaining the custom matrix?
Pete Thurston
executiveYes, absolutely. So it's Custom Metrics. And so the key with Security Center is, Security Center is built on a few pillars. One being the actual data that it needs to be able to know what's going on. And we call those metrics, right? So each data point that you see in Security Center is a metric. Historically, we -- Salesforce had to create those metrics. So we would define a metric called like users with modify all data, and we would write all the back-end logic to get it and put it into the application and then you would have that information. You could do stuff with it, including alerts and all the good stuff that comes with Security Center. What we ended up seeing was there were a lot of customers who had these like one-off things, but really, a lot of this came from the partner side, where customers were like, well, I work with a partner who does code scanning. Do you do code scanning? And we're like, well, not really in the way that you're talking about. So we started opening up the ability for people to define their own metric and put it into the system. And that's what Custom Metrics is. And so now that's going to go GA soon. We're really excited.
Moya McKay
executiveAwesome. Awesome. And then we do also have a few folks asking if the features that you shared today are available in every Salesforce or are they purchase edition only?
Pete Thurston
executiveSo everything that you saw today is purchasable products, including Shield and Security Center. They're available for all customers, but do need to be licensed.
Moya McKay
executiveGot it. Okay. And in reference to the Security Center license, is that different than Privacy Center?
Pete Thurston
executiveYes. Actually -- I'm actually -- I love that question, too, because it gives me a chance to get on my soapbox for a second, which is security and privacy are different things. They tend to get lumped in together because a lot of the same people care about them, and they tend to be related to regulations or compliance concerns. But privacy of data and security of data are different things, and Privacy Center does very different things than Security Center does. It handles things like GDPR requests as well as some data retention policies and other things that come along with privacy regulations.
Moya McKay
executiveCool. Okay. And we had a lot of questions come in around Event Log Objects. So I'm going to do my best to get some of these answered here. First and foremost, the first question I see here is, is Event Log Objects now available to Hyperforce customers and if we are located in EU with our product org?
Pete Thurston
executiveOkay. So yes, and so Event Log objects is available for Hyperforce customers. The current beta is U.S. only, but we are working to expand that as soon as we can. That's part of why it's in beta and not GA is because we are working on the global rollout right now. And so I can't give you a very specific date on it yet, but we are working on that right now. And by the time we call this thing fully GA, it will be available to the customer in question.
Moya McKay
executiveAwesome. Okay. Next question, again, on Event Log. How can we leverage the expanded event log file retention? And how do I know after I have checked the box that I'm now logging longer than 30 days?
Pete Thurston
executiveOkay. Yes. It's real, real easy. You just go to your Event Monitoring settings and turn on the toggle that says expanded retention. Just check it and you're good to go. And then how do you know, wait a day and query the event log file object and see if you have 31 of them instead of 30.
Moya McKay
executiveSimple enough, right?
Pete Thurston
executiveYes. And if you don't open a case, we'll take a look. But we got a lot of customers taking advantage of this, trust me, we keep a close eye on it.
Moya McKay
executiveAwesome. Let's see next question, again on Event Logs. Can you run a record triggered flow from the Event Log Objects?
Pete Thurston
executiveNot yet in the beta, but we are working on it. It's certainly something we want to be able to take action on. But right now, not yet.
Moya McKay
executiveOkay. And then last question on Event Log. Do Event Log Objects take up storage space on my product org?
Pete Thurston
executiveNo. So Event Log objects, similar to event log files and other and security center objects are -- allow listed basically and do not consume your storage allocation that comes with your licenses. That's part of why there's a data retention policy that we enforce.
Moya McKay
executiveAll right. So that concludes our Event Log Objects question. We just have a few more questions here. I know we're coming up on time. So just 1 or 2 more questions before we get a chance to wrap up. And again, for everyone that has asked a question, if we do not get a chance to answer your question today, we will be sure to follow up with you, just another general friendly reminder. So next question here is, could you please explain in database encryption why customer has to be -- has to buy it and why not use a standard encryption?
Pete Thurston
executiveYes, that's fair. I mean I'm assuming that the question, the spirit of the question, as I'm interpreting is what additional value comes with database encryption beyond the volume level encryption that we make available to all of our customers. And the answer to that is a bit nuanced to be clear. A big part of it is customer managed, customer control and customer specificity. So we have a lot of customers who -- as you know, if you're a customer of Salesforce, you know this already that we run a multi-tenant database. And all of our customers' database -- data can be co-mingled within the database. And therefore, when we do volume-level encryption at the disk tier or things like that, it has to be Salesforce controlled keys as we can't Salesforce own keys, and they are keys that we use to encrypt all of the data within that data store altogether. With database encryption, what we do is we are able to segment that in a way that gives you tenant-specific or customer-specific control of your key material to ensure that your data is controlled with keys that -- or is encrypted with keys that you control and that you have insight to the full life cycle. As far as what threat vectors database encryption assists with, if for some reason, our disks were to be compromised, but we're able to be mounted, they would not be able to inspect the information in the database for the customers who have this level of encryption included. And so that's the threat vector that we're addressing with database encryption as well as giving you the tenant specificity and the customer control over the life cycle.
Moya McKay
executivePerfect. All right. So thank you so much for answering those questions. We just have one more question here from the audience. It looks like a few folks were asking if you all could share links for the upcoming event that you all mentioned today?
Pete Thurston
executiveAbsolutely, yes.
Kirstin Meyerhoeffer
executiveYes, we can definitely do that.
Pete Thurston
executiveAs part of a follow-up on the event. And I know there are a few questions we weren't able to get to, but we'll try to get back to folks. I assume we have the ability to do that. We'll try to get back to you if we didn't get to your question today live on the webinar.
Moya McKay
executiveWonderful. Well, thank you all so much. And just a friendly reminder, again, here are the resources and the CTAs that Kirstin and Pete shared just a little bit earlier in today's session. So if you didn't get another -- get a chance to, go ahead and grab your phone, scan those QR codes, make sure that you're checking out everything here. And again, another reminder that you all will receive a link to watch today's presentation on demand. So just keep an eye out for that in your e-mail inbox. But once again, thank you all so much for joining us. Thank you for taking the time. Thank you for being interested in today's topic. And I'm sure Kirstin and Pete will love to see some of you guys at Dreamforce next week. So go ahead and make sure that you're connecting with them, that you find them and that you make sure you say, hey, that's not a bad idea, right? So all right. Well, thank you all so much -- yes, thank you all so much for coming. Thank you all for joining, and we hope you all have a great day.
Pete Thurston
executiveBye all.
Kirstin Meyerhoeffer
executiveBye.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Salesforce, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Salesforce, Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.