Sensitive Data Exposure
Production information may be copied into non-production environments during sandbox refreshes.
Salesforce sandbox data protection
Safely discover, classify and mask sensitive Salesforce data after sandbox refreshes—while giving teams visibility and control over every masking operation.
Designed for Salesforce teams managing sensitive data across non-production environments.
MASKING CONTROL PANEL
Sensitive fields
42
Objects covered
18
Last execution
Passed
Current masking job
68%Email, Phone
Address
Description
The challenge
Salesforce sandbox refreshes can bring sensitive production information into environments used for development, testing and implementation. Managing that information manually can become complex as organisations scale. Privacy Guard provides teams with a structured way to discover sensitive fields, configure masking policies and execute controlled data-protection processes.
Production information may be copied into non-production environments during sandbox refreshes.
Scripts and one-off processes can become difficult to maintain, monitor and audit.
Large Salesforce environments require repeatable protection without disrupting development and testing.
A structured approach
Discover. Configure. Mask. Validate. Audit.
Discover
Configure
Protect
Validate
Audit
Core capabilities
Purpose-built controls bring discovery, masking and operational visibility into one manageable experience.
Scan Salesforce metadata to help identify fields that may contain personally identifiable or sensitive information.
Configure masking and randomisation strategies for sensitive Salesforce fields.
Create and manage reusable masking jobs across selected Salesforce objects.
Support complete operations and targeted processing when selected data needs additional masking.
Manage relevant Salesforce automation during masking to reduce unwanted processing.
Restrict masking operations to authorised non-production environments.
Track executions, processed records, failures and detailed job information.
Use Salesforce permissions to control access to sensitive masking operations.
How it works
Scan Salesforce objects and identify fields that may contain sensitive information.
Select objects and fields and assign appropriate masking strategies.
Execute reusable masking jobs within authorised sandbox environments.
Review processing results and identify records requiring attention.
Maintain execution history and detailed operational logs.
Privacy Guard product experience
A clear operational workspace helps teams move from discovery to validated outcomes without losing context.

Masking strategies
Administrators can configure appropriate masking and randomisation strategies for email addresses, phone numbers, names, addresses, identifiers and custom sensitive fields based on organisational requirements.
Original
john.smith@example.comProtected
sandbox.x7k2@example.invalidSecurity by design
Privacy Guard is designed around controlled execution within Salesforce environments.
Help prevent masking jobs from running in unauthorised environments.
Control who can configure and execute sensitive masking operations.
Maintain visibility into job status, processing results and failures.
Maintain execution history to support operational governance.
Built for teams
Configure masking policies and manage sandbox protection.
Work with safer non-production datasets.
Integrate protection into environment-management processes.
Improve visibility and governance around sensitive non-production data.
Refresh workflow
See how Privacy Guard can help your teams discover sensitive data, automate masking and improve control over sandbox data protection.
Request a demo
Tell us about your Salesforce environment and data-protection goals. We'll tailor the conversation to your team's needs.
Explore discovery and masking workflows
Discuss your environment-management process
See operational controls and audit visibility