Salesforce integration security and privacy
Table of Contents
This article covers how Sprout Social handles data security, authentication, and privacy when connected to your Salesforce instance. Use this information when evaluating whether to approve the Sprout Social integration for your organization.
For comprehensive security documentation — including SOC 2 Type 2 reports, ISO certificates, penetration test results, and 100+ pre-answered security questions — visit our Customer Trust Portal.
Certifications and compliance
Sprout Social's security program is independently validated through:
SOC 2 Type 2 — Audited annually for each Sprout Social product
ISO 27001:2022 — Certified Information Security Management System
ISO 27701:2019 — Certified Privacy Information Management System
CSA STAR Level 1 — Cloud Security Alliance self-assessment (view on STAR Registry)
A Data Processing Addendum (DPA) covering GDPR and CCPA is available. Visit our Trust Center for details.
How authentication works
Sprout uses OAuth 2.0 to authenticate access to your Salesforce instance.
Credentials stored in Sprout's systems are short-lived tokens refreshed per Salesforce's standard OAuth 2 mechanism.
Sprout does not store your Salesforce username or password.
The integration authenticates as the specific Salesforce user who completes the OAuth connection. All actions taken by Sprout in Salesforce operate under that user's permission set.
You can revoke access at any time by disconnecting the integration in Sprout or revoking the Connected App in Salesforce Setup.
What data does Sprout store?
Almost nothing. All Salesforce data is live-queried — meaning every time a user views integration data in Sprout, we request it from Salesforce in real time, display it, and do not persist it.
The only data Sprout stores from your Salesforce instance is reference IDs (Contact ID, Case ID, Lead ID) used to maintain the link between social messages and Salesforce records.
Sprout does not store:
Contact names, emails, or phone numbers from Salesforce
Case content or history
Custom field data
Attachments or files
What data does Sprout send TO Salesforce?
The integration sends data to Salesforce only when a user explicitly creates or updates a record. With pre-fill functionality, this can include:
Social message content (the text of the inbound message)
Network profile data (display name, username/handle)
Sprout CRM data (email, phone — only if previously entered by a Sprout user)
Sprout metadata (tags applied to the message)
Case fields (subject, priority, status, owner)
Important: Sprout does not automatically push any data to Salesforce. Data only flows when triggered by:
A user manually creating a Contact, Lead, or Case from Sprout
An Automated Rule or Macro configured by your team to send messages to Salesforce
What API does Sprout use?
Sprout connects to Salesforce using the Salesforce REST APIs. The integration supports both Salesforce Lightning and Classic platforms.
For the Service Cloud integration, Sprout also installs a managed package in your Salesforce instance that includes:
A Flow Template for case routing
A Lightning Web Component (reply iframe)
Custom objects (Sprout Social Post, Sprout Social Persona)
Network and firewall considerations
Sprout Social is hosted on AWS and uses Cloudflare — both of which leverage dynamic IP addresses by design. We cannot guarantee static IP addresses.
Recommended approach
If your Salesforce instance restricts access by IP, we recommend:
Create a dedicated Salesforce user profile for the Sprout integration user.
Disable the IP restriction for that specific profile only (not your entire org).
Assign the minimum necessary permissions to that profile (Read, Create, Edit for Contacts, Leads, Cases).
This approach keeps your broader Salesforce org behind your firewall while allowing the integration user to authenticate.
If your organization requires IP allowlisting
We strongly discourage IP allowlisting because our infrastructure uses dynamic IPs. When IPs are added or changed, customers experience connection interruptions until they update their allowlist — creating ongoing maintenance overhead.
If your security policy absolutely requires allowlisting, contact Sprout Support for the current IP range. Be aware that:
These IPs may change without advance notice
Changes will cause service disruption until you update your allowlist
You are responsible for monitoring and updating the allowlist
Session settings
In Salesforce, navigate to Setup > Session Settings and confirm that "Lock sessions to the IP address from which they originated" is not enabled for the integration user's profile. This setting can cause intermittent failures when Sprout sends data to Salesforce.
Social user consent and data privacy
Sprout Social is compliant with the privacy and partner terms set by each social network (Meta, X/Twitter, LinkedIn, TikTok, Pinterest, etc.).
Social users consent to data use when they accept the terms of the social platform.
Sprout does not store or send any PII to integrations automatically.
Data only flows to Salesforce when explicitly triggered by your team's configured rules or manual actions.
Sprout acts as a Data Processor in relation to social data ingested from network partners and integration partners like Salesforce (per our Incident Handling and Notification Policy).
Integration availability and permissions
Requirement |
Detail |
|---|---|
Plan |
Advanced (as of March 1, 2024) |
Sprout permissions |
Account Owner, or Manage Profiles + Manage Advanced Inbox Features |
Salesforce permissions |
Read, Create, Edit for Contacts, Leads, and Cases. Admin-level access for managed package installation. |
Implementation |
Professional Services implementation is required for the Service Cloud integration |
Additional resources
Customer Trust Portal — SOC 2 reports, ISO certificates, pen test results, and 100+ Q&As
Trust Center — High-level overview of security, privacy, and compliance
Data Processing Addendum — DPA for GDPR and CCPA
How do I get started with Sprout's Salesforce Service Cloud integration? — Setup guide
How can I use Salesforce in Sprout? — Feature guide and FAQ
FAQ
We have a firewall in place. Can we allowlist Sprout IP addresses?
Sprout can't guarantee or provide a list of static IPs. We use AWS and Cloudflare which leverage dynamic IPs.
To allow Sprout traffic, we recommend creating a new Salesforce user profile for the integration user that is used when connecting Sprout and disabling the IP restriction.
Our organization requires that specific IP addresses are allowlisted. Can you provide a range?
We discourage allowlisting because when IPs are added or changed, customers can experience connection interruptions until they update their allowlist databases. This maintenance overhead can be burdensome.
We can provide these IP addresses; however, due to our systems being dynamic, there is the possibility that an IP address changes, which will result in service disruption.
- 34.195.143.64
- 34.231.199.169
- 34.226.188.226
- 52.6.6.24
What API does Sprout use to connect to Salesforce?
Sprout uses the Salesforce REST APIs to connect to Salesforce.
How does authentication with Salesforce work?
Sprout uses OAuth 2 to authenticate Sprout’s access to a Salesforce instance. The credentials stored in Sprout’s systems are short-lived and are refreshed per Salesforce’s exposed OAuth 2 mechanism.
What Salesforce data does Sprout store?
All data is live-queried and nothing is stored within the Sprout system except for ID information such as contact ID and case ID.
What data does Sprout have access to?
The integrations have access to whatever data the customer "pushes" to the integration by creating a new entity. With our pre-fill functionality, this data can include:
- Message data
- Network profile data such as name, username
- Sprout CRM data such as email address, phone number, etc.
- Sprout metadata, such as tags
Do social users opt-in or consent to data being transferred to a CRM tool?
For our integrations, we are compliant with the privacy and partner terms set by the social networks. The end user opts in when they accept the terms of the social platform. Sprout Social does not store or send any PII data to our integrations automatically.
Was this article helpful?