AgentCloak for Agentforce
Expand your Agentforce globally with agentic data residency.
Comply with cross-border AI requirements
Bidirectional data cloaking powered by Sovereign AI’s
Uses a Sovereign AI in each country to detect PII, PHI, and PCI data, cloak data before it leaves the country, and uncloak on return.
Seamless integration with Agentforce and Einstein
Integrated with Agentforce across messaging, email, Service Console, Sales Engagement, and more.
Governed digital twin secured with full data residency
Maintain secure digital twins with custom schemas in each country, governed by Salesforce fine-grained authorization.

Full agentic data residency with global Agentforce agents
- Comply with EU AI Act and minimize the burden of cross-border AI data transfers.
- Seamlessly substitute sensitive data and restore original values.
- Replace protected data with flexible tokenization, hashing, and masking strategies.
- Identifies multiple participants in a single conversation, such as “I’m writing about my father”.
- Generalizes ages and weights into brackets, health terms like “headache” into “minor neurological condition,” addresses into regions, and more.

Integrates with all Agentforce Service Agent channels
- Maintains a secure digital twin in the country for each customer.
- Cloaks and unclocks sensitive data in real-time during conversations between customers and Agentforce Agents.
- Integrates with In-App messaging and Web channel communications from cross-border customers.
- Email-to-Case fully supported with local Email servers that cloak and uncloak sensitive data.
- Local memory of each customer’s context history with Agentforce Agents.

Full data residency in Salesforce Service Console
- Complete human-in-the-middle data residency with Service Console and Service Agents using only cloaked data.
- Local customer representatives work directly with unclocked data in Service Console while maintaining full data residency.
- Local customers seamlessly work with uncloaked data.

Fully integrated with Email-to-Case with local email support.
- Local email automatically captures and processes inbound customer emails
- AI-powered clocking automatically detects sensitive information into a secure digital twin, including names, phone numbers, email addresses, and account details.
- Case and Email Message records are stored in the global Salesforce org in cloaked form
- Customer service agents in a country can see uncloaked emails directly in Salesforce Service Console.

Local Sovereign AI generation drives Einstein Service Replies
- Einstein Service Replies uses AgentCloak’s local Sovereign AI to combine user data with knowledge suggestions.
- AgentCloak dynamically inserts the uncloaked data into outgoing emails.
- Salesforce only stores cloaked data to ensure regulatory compliance.

Local Sovereign AI support for Employee Agent
- Local sales and customer service representatives work directly with Employee Agent.
- InCountry cloaks and uncloaks sensitive data processed by Employee Agent’s actions.
- Summarize any Salesforce record locally with a Sovereign AI even when regulated fields aren’t stored in the global Salesforce org.

Using Einstein? We add data residency!
- Sales or Service representatives can ask Einstein to perform actions like drafting a new email.
- Einstein AI generates emails using cloaked data which is then uncloaked by a local email server using the secure digital twin.

Data protection and cross-border support for Salesforce MCP Server
- Automatically enforce data cloaking policies when using group accounts to access data
- Extend a Salesforce MCP Server across borders with automatic cloaking and uncloaking of MCP Client prompts.
Interested in learning more about
AgentCloak for Agentforce?
Request a demo with one of our architects.