Deep-dive on the Next Gen Platform. Join the Webinar!

Skip Navigation
Show nav
Dev Center
  • Get Started
  • Documentation
  • Changelog
  • Search
  • Get Started
    • Node.js
    • Ruby on Rails
    • Ruby
    • Python
    • Java
    • PHP
    • Go
    • Scala
    • Clojure
    • .NET
  • Documentation
  • Changelog
  • More
    Additional Resources
    • Home
    • Elements
    • Products
    • Pricing
    • Careers
    • Help
    • Status
    • Events
    • Podcasts
    • Compliance Center
    Heroku Blog

    Heroku Blog

    Find out what's new with Heroku on our blog.

    Visit Blog
  • Log inorSign up
Hide categories

Categories

  • Heroku Architecture
    • Compute (Dynos)
      • Dyno Management
      • Dyno Concepts
      • Dyno Behavior
      • Dyno Reference
      • Dyno Troubleshooting
    • Stacks (operating system images)
    • Networking & DNS
    • Platform Policies
    • Platform Principles
  • Developer Tools
    • Command Line
    • Heroku VS Code Extension
  • Deployment
    • Deploying with Git
    • Deploying with Docker
    • Deployment Integrations
  • Continuous Delivery & Integration (Heroku Flow)
    • Continuous Integration
  • Language Support
    • Node.js
      • Working with Node.js
      • Troubleshooting Node.js Apps
      • Node.js Behavior in Heroku
    • Ruby
      • Rails Support
      • Working with Bundler
      • Working with Ruby
      • Ruby Behavior in Heroku
      • Troubleshooting Ruby Apps
    • Python
      • Working with Python
      • Background Jobs in Python
      • Python Behavior in Heroku
      • Working with Django
    • Java
      • Java Behavior in Heroku
      • Working with Java
      • Working with Maven
      • Working with Spring Boot
      • Troubleshooting Java Apps
    • PHP
      • PHP Behavior in Heroku
      • Working with PHP
    • Go
      • Go Dependency Management
    • Scala
    • Clojure
    • .NET
      • Working with .NET
  • Databases & Data Management
    • Heroku Postgres
      • Postgres Basics
      • Postgres Getting Started
      • Postgres Performance
      • Postgres Data Transfer & Preservation
      • Postgres Availability
      • Postgres Special Topics
      • Migrating to Heroku Postgres
    • Heroku Key-Value Store
    • Apache Kafka on Heroku
    • Other Data Stores
  • AI
    • Working with AI
  • Monitoring & Metrics
    • Logging
  • App Performance
  • Add-ons
    • All Add-ons
  • Collaboration
  • Security
    • App Security
    • Identities & Authentication
      • Single Sign-on (SSO)
    • Private Spaces
      • Infrastructure Networking
    • Compliance
  • Heroku Enterprise
    • Enterprise Accounts
    • Enterprise Teams
    • Heroku Connect (Salesforce sync)
      • Heroku Connect Administration
      • Heroku Connect Reference
      • Heroku Connect Troubleshooting
  • Patterns & Best Practices
  • Extending Heroku
    • Platform API
    • App Webhooks
    • Heroku Labs
    • Building Add-ons
      • Add-on Development Tasks
      • Add-on APIs
      • Add-on Guidelines & Requirements
    • Building CLI Plugins
    • Developing Buildpacks
    • Dev Center
  • Accounts & Billing
  • Troubleshooting & Support
  • Integrating with Salesforce
  • Security
  • Compliance
  • Heroku Security, Privacy, and Compliance

Heroku Security, Privacy, and Compliance

English — 日本語に切り替える

Last updated December 03, 2024

Table of Contents

  • Shared responsibility model
  • Audits and Certifications
  • Heroku Security Features

When you build and operate a mission critical application on Heroku, you are entrusting Salesforce with critical and sensitive data about your business and about your customers. Nothing is more important to us than protecting the privacy of your data and that is why Trust is our number one value.

Shared responsibility model

Developers around the world entrust sensitive data to Heroku, and nothing is more important to Salesforce than trust and protecting this data. However, protecting your data is a shared responsibility between Salesforce and you, our customer.

Salesforce’s responsibility is to architect systems for optimal security. This means implementing and enforcing effective practices and processes controlling how our team accesses and operates Heroku Services. Salesforce is also responsible for regularly hosting third-party audits of Heroku Services and critical vendors, and maintaining certifications to verify the security of our systems and processes.

As a Heroku customer, you are part of the team that keeps your apps safe. You are responsible for implementing strong security measures in your applications and for properly managing access to your Heroku account and resources. Heroku offers many security features to help you with this responsibility.

Audits and Certifications

To see which certifications a particular product has, refer to the certification scope table. We are still working on obtaining certifications for the Fir-generation of Private Spaces.

Heroku regularly performs audits and maintains a number of certifications to further strengthen our trust with customers and to enable Heroku customers to build certified applications on the platform. The detailed list of audits and certifications is maintained in the Security Privacy and Architecture (“SPARC”) document for Heroku, which is part of the Heroku Enterprise Master Subscription Agreement, and compliance resources are available on the Salesforce Trust website (Salesforce Services login required) or via logging a ticket here. These include:

PCI

Salesforce has an Attestation of Compliance as a PCI Level 1 Service Provider covering Heroku Shield Services offered as part of Heroku Enterprise. Customers can contact the Heroku sales team for additional information on Heroku’s PCI compliant offerings.

HIPAA

Customers who want to build healthcare applications on Heroku that comply with US HIPAA can contact the Heroku sales team regarding a Business Associate Addendum to the Master Subscription Agreement that is required for HIPAA compliance.

GDPR

Please see the GDPR Dev Center article for details on how EU General Data Protection Regulation is relevant for apps on Heroku.

ISO 27001, 27017, and 27018 Certification

Salesforce has been certified against this set of widely recognized and internationally accepted information security standards that specifies security management best practices and comprehensive security controls following ISO 27002. These certifications also cover information security specific to the cloud the protection of Personally Identifiable Information (PII).

SOC 1, 2, and 3 Attestation Reports

Salesforce has been issued SOC1, 2 and 3 reports by an independent auditor. The SOC1 Type II is an independent examination of the IT General controls and controls around availability, confidentiality and security of customer data processed by the Heroku Platform relevant for the financial reporting of customers. The SOC2 Type 2 is a restricted to use report and independent examination of the fairness of presentation and the suitability of the design of controls relevant to security, availability and confidentiality of the customer data processed by the Heroku Platform. The general use SOC3 report is an independent examination of the fairness of presentation and the suitability of the design of controls relevant to security, availability and confidentiality of the customer data processed by the Heroku Platform.

Heroku Security Features

Heroku has a number of customer configurable features that help you keep your Heroku deployments secure. You can find more information regarding these features in the article Heroku Security & Compliance Resources and Features.

Keep reading

  • Compliance

Feedback

Log in to submit feedback.

Information & Support

  • Getting Started
  • Documentation
  • Changelog
  • Compliance Center
  • Training & Education
  • Blog
  • Support Channels
  • Status

Language Reference

  • Node.js
  • Ruby
  • Java
  • PHP
  • Python
  • Go
  • Scala
  • Clojure
  • .NET

Other Resources

  • Careers
  • Elements
  • Products
  • Pricing
  • RSS
    • Dev Center Articles
    • Dev Center Changelog
    • Heroku Blog
    • Heroku News Blog
    • Heroku Engineering Blog
  • Twitter
    • Dev Center Articles
    • Dev Center Changelog
    • Heroku
    • Heroku Status
  • Github
  • LinkedIn
  • heroku.com
  • Terms of Service
  • Privacy (日本語)
  • Cookies
  • Cookie Preferences
  • Your Privacy Choices
  • © 2025 Salesforce.com