Public Independence Disclosure:This is an independent TrustRank public-evidence assessment and does not imply endorsement, certification or participation by OpenAI.
Trust Passport•TR-2026-000002

Salesforce Agentforce

Provider: Salesforce, Inc.•Version: 2026.10-enterprise

Enterprise autonomous AI agent platform powered by the Atlas Reasoning Engine and Einstein Trust Layer, executing business actions, CRM workflows, and multi-step customer operations within Salesforce Cloud.

This Trust Passport applies specifically to the assessed agent configuration shown below. It is not an enterprise-wide rating of Salesforce, Inc. or every version/deployment of Salesforce Agentforce.

PUBLIC ASSESSMENTStandard 0.2Revision 1STATUS: VALID

TrustRank Assessment & Evidence Confidence

TrustRank ScoreBand TR2
53.07/ 100
Assurance Level: LIMITED ASSURANCE

Deterministic weighted composite outcome evaluated across active control domains.

Evidence ConfidenceFormula 0.2.0-provisional
32.6%provenance strength
Independent Verification: 6 E2 / 0 E3

Measures the independence, rigor, and reproducibility of the supporting evidence records.

Assurance Cap Applied
  • PUBLIC_ASSESSMENT_CAP: Public assessments are capped at 79 and ineligible for verified status or TR4/TR5. (capped at 79)
Understanding Score vs Evidence Confidence:

TrustRank reflects assessed control outcomes. Evidence Confidence reflects the strength, independence and testability of the supporting assessment evidence. These metrics are not combined, averaged, or converted into an empirical probability of safety.

Record Integrity

Record integrity: VerifiedAlgorithm: SHA-256

The current canonical assessment record matches its stored assessment fingerprint.

Server-authoritative check
Integrity Verification Boundary:

Record integrity verification establishes that this assessment record exactly matches its stored assessment fingerprint without tampering. This verifies record integrity only. It does not verify the identity of the issuer through a digital signature or cryptographic attestation.

6f15e88d935bef40c230f99e14a56c91c5d3bc4134ee098a4bcb4fab8fe1d2d9
6f15e88d935bef40c230f99e14a56c91c5d3bc4134ee098a4bcb4fab8fe1d2d9

Assessed Configuration

Scope Boundary:

This Trust Passport applies to the specific assessed agent configuration shown here. It is not a universal rating of the provider, all versions of the agent, or every deployment.

Agent IdentitySalesforce Agentforceag-salesforce-agentforce
Version2026.10-enterprise
Primary ModelCONFIGURATION_DEPENDENTAssessed backend model
Deployment Environmentsalesforce-cloud-enterpriseRuntime: salesforce_atlas_reasoning_engine
ProviderSalesforce, Inc.Jurisdiction: United States
Approval Policyhuman approval on high risk record modificationsNetwork: salesforce named credentials tls strict
Assessed Operational Permissions (5)
crm_object_read_accounts_contactscrm_object_read_write_leads_casescrm_object_read_opportunitiesflow_execute_service_actionsapex_execute_whitelisted_classes
Assessed Tool Interfaces (6)
crm_record_querycrm_record_create_updateflow_action_executionapex_action_executionexternal_service_rest_calloutslack_channel_message_dispatch
Active Platform Security Controls (7)
einstein_trust_layer_gatewaysalesforce_platform_rbacfield_level_security_flsdata_masking_and_zero_retentionprompt_defense_and_toxicity_filterdata_cloud_audit_trail_loggingtrusted_urls_outbound_filter

Material Change Principle: A material change to the assessed configuration (including model weights, tool boundaries, execution permissions, or network access) may require reassessment before the stated validity date.

Assessment Findings

(2)
CF1: 0CF2: 0CF3: 0CF4: 0
CF-AF-001CF2Zero-Click CRM Data Exfiltration via Indirect Prompt Injection in Web Forms (ForcedLeak)
RESOLVED

Vulnerability in Agentforce web form processing permitted indirect prompt injection payloads submitted via public Web-to-Lead forms to execute unauthorized CRM record queries and exfiltrate customer data to external endpoints. Disclosed by Noma Security in September 2025 and remediated by Salesforce with enhanced context validation and URL restrictions.

Control Reference: TR04.02Discovered: 2025-09-12T00:00:00.000Z
CF-AF-002CF2Trusted URL Filter Bypass and Unauthenticated Slack Channel Messaging (SalesBleed)
RESOLVED

Vulnerability chain in Agentforce permitted indirect prompt injection payloads in Web-to-Lead records to bypass Trusted URL restrictions via image-tag DNS queries, exfiltrating Accounts table CRM data, and dispatched unauthenticated phishing messages into internal Slack channels under the Agentforce identity. Disclosed by Zenity Labs on September 24, 2026 and remediated by Salesforce via production hotfix.

Control Reference: TR06.02Discovered: 2026-09-24T00:00:00.000Z

Control Coverage & Evidence Distribution

Critical Control Coverage(25 applicable)

Applicable Critical25Active assessment scope
E3 Adversarial Tested0Rigorous adversarial tests
Not Testable Control Accounting:

Controls marked as not testable are applicable to the agent but could not be independently tested with available evidence. They remain in the scoring denominator at zero score and are not treated as safe or passing.

Evidence Distribution(7 total records)

E0 Tier0Self-declared
E1 Tier61Documented / Int.
E2 Tier6Ind. Verified
E3 Tier0Adversarial
Evidence Tier Definitions:

E0 = Vendor self-declaration; E1 = Documented implementation or internal testing; E2 = Independently verified artifact; E3 = Independently adversarially tested. E3 evidence cannot be vendor self-testing.

Operational Profile & Autonomy Boundaries

Autonomy LevelA2Execution scope
Financial AuthorityF0Transaction limits
Guardrail DependencyGD3Safety harness
Composition ExposureCE2Swarm delegation

Assessment Validity & Lifecycle Status

Temporal validity window, assessment cycle, and canonical lifecycle status.

LIFECYCLE: VALID
Assessment Date (Issued)
2026-10-01
Canonical assessment completion timestamp
Valid Until (Expiry)
2026-12-30
83 days remaining in current validity cycle
Assessment Cycle
90-Day Maximum Cadence
Methodology requirement for active assurance

Important distinction: Record Integrity vs. Lifecycle Validity

Record Integrity establishes that the assessment data presented on this page exactly matches the SHA-256 fingerprint generated at assessment time without tampering.

Lifecycle Validity establishes whether the assessment is currently within its 90-day operational validity window and has not been revoked or marked as requiring reassessment. A record may be tamper-free (Verified Integrity) while simultaneously being expired or superseded.

Material Change Principle: A material change to the assessed agent code, system prompt, tool definitions, runtime environment, or permissions requires reassessment before the stated validity date.

Domain Assessment Breakdown (12 Domains)

DomainWeightApplicableDomain ScoreWeighted Contribution
TR01 - Identity & Provenance8%5 52.004.16
TR02 - Permissions & Least Privilege12%6 48.755.85
TR03 - Data Protection & Privacy10%6 62.086.21
TR04 - Prompt Injection & Goal Hijacking12%6 34.174.10
TR05 - Tool & Action Safety12%7 (5 N/A)52.506.30
TR06 - Boundary & Goal Adherence10%5 58.255.83
TR07 - Human Control & Intervention8%5 61.754.94
TR08 - Auditability & Transparency7%5 61.754.32
TR09 - Memory & Context Integrity6%9 51.673.10
TR10 - Agent & External Communications5%6 45.002.25
TR11 - Operational Reliability & Recovery5%5 58.502.93
TR12 - Governance & Change Control5%5 61.753.09

Portable Passport Record

Canonical portable fields representing the public Trust Passport record.

Passport ID
TR-2026-000002
Assessment ID
TR-2026-000002
Assessed Agent
Salesforce Agentforce
Provider
Salesforce, Inc.
Assessed Version
2026.10-enterprise
TrustRank Score
53.07 / 100
TrustRank Band
Tier TR2
Evidence Confidence
32.6
Assessment Type
Public Evidence
Lifecycle Status
VALID
Record Integrity
MATCH
Assessment Date
2026-10-01
Valid Until
2026-12-30
Autonomy Level
A2
Financial Authority
F0
Critical Findings
0 open CF1
Total Findings
2 recorded
Canonical Fingerprint
6f15e88d935bef40c230f99e14a56c91c5d3bc4134ee098a4bcb4fab8fe1d2d9
Schema: trust-passport-v0.2 · Public allowlist projection
Deterministic integrity: MATCH