Your team owns your Salesforce org. When a digital threat enters, you also own the fallout.
Salesforce's native scanner does not prevent your own users from unknowingly uploading a threat.
It was never built for attackers like ShinyHunters who target Salesforce customers, so teams relying on it are not protected. Salesforce Scanner is a checkbox. EzProtect reads every file and every link, and blocks it until it is proven safe without compromising functionality.
Catches an executable renamed to .png, which file-type checks wave through
Trusted by Fortune 500, public sector, and regulated industries
11+ years securing Salesforce
Powered by the Sophos engine
100% US-based, AWS GovCloud
Trusted by Fortune 500, public sector, and regulated industries
We uploaded a real trojan to Salesforce's Summer '26 scanner. It let the file through. EzProtect caught and blocked it.
A renamed executable, a malicious link in a PDF, a zero-day with no signature. Native scanning flags only the obvious. EzProtect reads every file and link and holds each one until it is proven safe.
In a 30-minute demo, watch EzProtect catch what it misses across Experience Cloud portals, Email-to-Case, and API uploads.
Attackers can test against the same scanner you run.
The native scanner is free and identical in every Salesforce org. An attacker can run the same scanner you do, confirm a file slips through, and only then aim it at you. The limits are public, so a file built to clear them clears them everywhere.
Native scanning is a checkbox.
EzProtect is a security layer.
Salesforce added a first layer. For orgs that take files from the public, partners, or APIs, the gap between the two is where breaches start.
Capability
Salesforce native, Summer '26
EzProtect
Detection method
Salesforce native, Summer '26
Not disclosed, flags only files with a high probability of being malicious
EzProtect
Signature, behavioral, and true file type, all testable
Disguised files (.exe renamed to .png)
Salesforce native, Summer '26
File-type controls rely on extension and MIME type, both can be alterered
EzProtect
Reads actual file content with true file type detection
Zero-day and unknown threats
Salesforce native, Summer '26
High-probability cases only
EzProtect
Behavioral analysis in an isolated sandbox
Malicious URLs and links
Salesforce native, Summer '26
Not scanned for
EzProtect
Scanned across fields and objects against live threat intel
File size scanned
Salesforce native, Summer '26
100 MB or smaller. Accepts 10 GB files unscanned.
EzProtect
Up to 2 GB per file
Trust model
Salesforce native, Summer '26
Blocks interface uploads. Lets API uploads in first.
EzProtect
No file moves until scanning proves it safe. Takes seconds.
"For us, a single miss is not an option. EzProtect scans up to 4.5 million files a month across our Salesforce environment, and it gives
us the confidence of knowing our data is protected."
— Director of IT, U.S. Federal Agency
Book your EzProtect demo.
See what the native scanner misses in your own org. Enter your details and a Salesforce security specialist will reach out to schedule a 30-minute walkthrough.
Let us know if there is a security topic that you are looking to learn about.
Be one of the first to know when the next super awesome Salesforce security blog has been released.
Our site uses cookies and other technologies so that we, and our partners, can remember you and understand how you use our site. For more information view our privacy policy.
OK