Configuring Your Account
Understand Billing
Publishing
Analytics & Reporting
Engagement
AI and Automation
Social Listening
Sprout Integrations
Tagging
Customer Care
Salesforce Service Cloud
Instagram
Facebook
X
Tiktok
Threads
WhatsApp
LinkedIn
YouTube
Pinterest
Bluesky

Salesforce integration security and privacy

Table of Contents

This article covers how Sprout Social handles data security, authentication, and privacy when connected to your Salesforce instance. Use this information when evaluating whether to approve the Sprout Social integration for your organization.

For comprehensive security documentation — including SOC 2 Type 2 reports, ISO certificates, penetration test results, and 100+ pre-answered security questions — visit our Customer Trust Portal.


Certifications and compliance

Sprout Social's security program is independently validated through:

  • SOC 2 Type 2 — Audited annually for each Sprout Social product

  • ISO 27001:2022 — Certified Information Security Management System

  • ISO 27701:2019 — Certified Privacy Information Management System

  • CSA STAR Level 1 — Cloud Security Alliance self-assessment (view on STAR Registry)

A Data Processing Addendum (DPA) covering GDPR and CCPA is available. Visit our Trust Center for details.


How authentication works

Sprout uses OAuth 2.0 to authenticate access to your Salesforce instance.

  • Credentials stored in Sprout's systems are short-lived tokens refreshed per Salesforce's standard OAuth 2 mechanism.

  • Sprout does not store your Salesforce username or password.

  • The integration authenticates as the specific Salesforce user who completes the OAuth connection. All actions taken by Sprout in Salesforce operate under that user's permission set.

  • You can revoke access at any time by disconnecting the integration in Sprout or revoking the Connected App in Salesforce Setup.


What data does Sprout store?

Almost nothing. All Salesforce data is live-queried — meaning every time a user views integration data in Sprout, we request it from Salesforce in real time, display it, and do not persist it.

The only data Sprout stores from your Salesforce instance is reference IDs (Contact ID, Case ID, Lead ID) used to maintain the link between social messages and Salesforce records.

Sprout does not store:

  • Contact names, emails, or phone numbers from Salesforce

  • Case content or history

  • Custom field data

  • Attachments or files


What data does Sprout send TO Salesforce?

The integration sends data to Salesforce only when a user explicitly creates or updates a record. With pre-fill functionality, this can include:

  • Social message content (the text of the inbound message)

  • Network profile data (display name, username/handle)

  • Sprout CRM data (email, phone — only if previously entered by a Sprout user)

  • Sprout metadata (tags applied to the message)

  • Case fields (subject, priority, status, owner)

Important: Sprout does not automatically push any data to Salesforce. Data only flows when triggered by:

  • A user manually creating a Contact, Lead, or Case from Sprout

  • An Automated Rule or Macro configured by your team to send messages to Salesforce


What API does Sprout use?

Sprout connects to Salesforce using the Salesforce REST APIs. The integration supports both Salesforce Lightning and Classic platforms.

For the Service Cloud integration, Sprout also installs a managed package in your Salesforce instance that includes:

  • A Flow Template for case routing

  • A Lightning Web Component (reply iframe)

  • Custom objects (Sprout Social Post, Sprout Social Persona)


Network and firewall considerations

Sprout Social is hosted on AWS and uses Cloudflare — both of which leverage dynamic IP addresses by design. We cannot guarantee static IP addresses.

If your Salesforce instance restricts access by IP, we recommend:

  1. Create a dedicated Salesforce user profile for the Sprout integration user.

  2. Disable the IP restriction for that specific profile only (not your entire org).

  3. Assign the minimum necessary permissions to that profile (Read, Create, Edit for Contacts, Leads, Cases).

This approach keeps your broader Salesforce org behind your firewall while allowing the integration user to authenticate.

If your organization requires IP allowlisting

We strongly discourage IP allowlisting because our infrastructure uses dynamic IPs. When IPs are added or changed, customers experience connection interruptions until they update their allowlist — creating ongoing maintenance overhead.

If your security policy absolutely requires allowlisting, contact Sprout Support for the current IP range. Be aware that:

  • These IPs may change without advance notice

  • Changes will cause service disruption until you update your allowlist

  • You are responsible for monitoring and updating the allowlist

Session settings

In Salesforce, navigate to Setup > Session Settings and confirm that "Lock sessions to the IP address from which they originated" is not enabled for the integration user's profile. This setting can cause intermittent failures when Sprout sends data to Salesforce.


Sprout Social is compliant with the privacy and partner terms set by each social network (Meta, X/Twitter, LinkedIn, TikTok, Pinterest, etc.).

  • Social users consent to data use when they accept the terms of the social platform.

  • Sprout does not store or send any PII to integrations automatically.

  • Data only flows to Salesforce when explicitly triggered by your team's configured rules or manual actions.

  • Sprout acts as a Data Processor in relation to social data ingested from network partners and integration partners like Salesforce (per our Incident Handling and Notification Policy).


Integration availability and permissions

Requirement

Detail

Plan

Advanced (as of March 1, 2024)

Sprout permissions

Account Owner, or Manage Profiles + Manage Advanced Inbox Features

Salesforce permissions

Read, Create, Edit for Contacts, Leads, and Cases. Admin-level access for managed package installation.

Implementation

Professional Services implementation is required for the Service Cloud integration


Additional resources

FAQ

We have a firewall in place. Can we allowlist Sprout IP addresses?
Sprout can't guarantee or provide a list of static IPs. We use AWS and Cloudflare which leverage dynamic IPs. 

To allow Sprout traffic, we recommend creating a new Salesforce user profile for the integration user that is used when connecting Sprout and disabling the IP restriction. 

Our organization requires that specific IP addresses are allowlisted. Can you provide a range?

We discourage allowlisting because when IPs are added or changed, customers can experience connection interruptions until they update their allowlist databases. This maintenance overhead can be burdensome.

We can provide these IP addresses; however, due to our systems being dynamic, there is the possibility that an IP address changes, which will result in service disruption.  

  • 34.195.143.64
  • 34.231.199.169
  • 34.226.188.226
  • 52.6.6.24

What API does Sprout use to connect to Salesforce?
Sprout uses the Salesforce REST APIs to connect to Salesforce.

How does authentication with Salesforce work?
Sprout uses OAuth 2 to authenticate Sprout’s access to a Salesforce instance. The credentials stored in Sprout’s systems are short-lived and are refreshed per Salesforce’s exposed OAuth 2 mechanism.

What Salesforce data does Sprout store?
All data is live-queried and nothing is stored within the Sprout system except for ID information such as contact ID and case ID.

What data does Sprout have access to?
The integrations have access to whatever data the customer "pushes" to the integration by creating a new entity. With our pre-fill functionality, this data can include:

  • Message data
  • Network profile data such as name, username
  • Sprout CRM data such as email address, phone number, etc.
  • Sprout metadata, such as tags

Do social users opt-in or consent to data being transferred to a CRM tool?
For our integrations, we are compliant with the privacy and partner terms set by the social networks. The end user opts in when they accept the terms of the social platform. Sprout Social does not store or send any PII data to our integrations automatically.

Was this article helpful?

0 out of 0 found this helpful

Table of Contents