Salesforce ensures that security is a focus of B2C Commerce development and provides secure development and platform-level security.
Salesforce secure development lifecycle (SSDL) delivers security at every stage of the development process. The SSDL provides education, industry-leading processes, and tools to ensure predictability, accountability, and transparency. Secure development best practices include defense in depth, least privilege, secure defaults, and regular static and dynamic vulnerability analyses.
Salesforce secure development lifecycle:
B2C Commerce takes a defense in depth approach when protecting its production environments. This approach includes multiple security controls at the application, infrastructure, and network levels to ensure that customer data is securely processed and stored.
The multiple applications that make up B2C Commerce provide strong authentication mechanisms. You can authorize authenticated users to access various parts of the application depending on their role. The SSDL ensures that these features provide security controls that protect the users while enabling customization.
We notify customers of security advisories related to the B2C Commerce platform on the Security Advisories site.
The Commerce Cloud Security model regarding actions taken by Salesforce employees on customer realms includes transparent logging of all sensitive areas. For more information, see Security Event Auditing.