Skip to main content
New tool CRON Expression Builder — preview next run times before you schedule Apex. Open the builder →
3D rendered network node illustrating secure Salesforce Private Connect data pathways for AI.
Agentforce & AI

Private Connect for Secure AI with Agentforce

Private Connect gives Agentforce and Data 360 a private, audited network path into customer data, which is what gets AI work past security review in regulated industries. Provisioning is down to minutes, and it now runs across multiple clouds.

Key takeaways Governance is where AI adoption stalls. Strict security and governance policies in regulated industries restrict the data Agentforce and Data 360 need to reach. Private Connect gives a private, auditable network path between customer environments and Salesforce services, bypassing the public internet. Provisioning has gone from weeks to under 30 minutes through automation and a managed control plane. The v2.0 architecture, built on private links and direct endpoints, improves throughput and cuts operational complexity. Multi-cloud support covers AWS and Azure, plus a growing list of data connectors. Meeting the security requirements is what makes an AI initiative approvable, and approval is the thing that sets the pace of adoption.

Private Connect and AI adoption in regulated industries

Agentforce and Data 360 projects tend to stall on data governance and security long before anyone questions what the model can do. The data those tools want sits behind strict firewalls and private network controls, and standard TLS encryption does not satisfy a policy that mandates a private, dedicated path. Without a connectivity layer that meets those demands, the AI work sits in soql-in-loops-security-review-impact-for-managed-packages/" class="auto-link">security review.

Private Connect is that layer: a private, auditable, dedicated network path between customer environments and Salesforce services, including Data 360, Agentforce, Tableau, CRM Analytics and GovCloud, with no traffic crossing the public internet. It is a secure, audited, encrypted path aimed squarely at what regulated sectors actually enforce.

Secure connectivity in minutes rather than weeks

Setting this up used to mean VPN tunnels, firewall rules and cross-cloud infrastructure to manage, and it took weeks or months even for teams who had done it before. The architecture was re-engineered onto shared infrastructure, automation and a managed control plane, which brings provisioning down to under 30 minutes. Customers can stand up a secure connection without deep networking expertise on staff.

That is what moves an AI timeline. Nobody is left maintaining a DIY setup, because the service is managed end to end.

Re-architecting for scale and performance

The first architecture had to carry cross-region traffic before the cloud platforms supported it natively, so it was built on site-to-site VPNs and proxy layers. That meant virtual machines to run, AMIs to patch and several infrastructure layers to keep alive. When Data 360 arrived with its throughput and latency requirements, the design needed more than another round of patching.

Private Connect v2.0 is built on private links, transit gateways and direct endpoint connectivity. Traffic flows directly between Salesforce endpoints and customer environments, which removes hops, cuts operational complexity and improves performance. It also gives the team a reusable foundation, so patching and automation cycles land faster.

As Hyperforce expanded globally, coordinating each new region by hand became the bottleneck. The control plane was rebuilt with automated pipelines for onboarding regions, and moving from manual coordination to API-driven processes lowers operational risk as that expansion continues. Private Connect currently carries around 120 TB of data and 683 million requests a month across 15 AWS regions.

Multi-cloud scale and flexibility

Customer environments differ, so compute and storage traffic have to be handled on the customer's terms. Endpoint management is decoupled, which lets customers configure connectivity independently and copes with how each cloud provider behaves (AWS, Azure), which DNS mechanism is in play, and when features ship.

The platform expands automatically as endpoint limits rise. Instead of a bespoke integration per data store, a generic connector framework is being built for the less common sources. The principle is that the architecture adapts to the customer, rather than the customer adapting to the architecture.

On Azure, Private Connect uses industry-standard, cloud-specific cross-substrate interconnects, so it plugs into whatever connectivity solution and underlying infrastructure that cloud offers.

Where the connectivity layer goes next

Private Connect started as an AWS-only feature and now spans multiple clouds, with connectors for Snowflake, Databricks, Redshift, Athena and Kafka. Headless 360 and MCP endpoints keep expanding, multi-cloud deployments are common, and agent traffic brings its own patterns, all of which want a connectivity layer that works platform-wide.

The stated philosophy is to redesign when the assumptions break instead of layering on incremental fixes. v2.0 is built to carry workloads well beyond current demand and to reach new clouds, protocols and services.

As Agentforce and Data 360 move to the center of enterprise AI, the connectivity underneath them matters as much as the models. An architecture the security team can approve is what lets the AI work start at all.

Originally reported by engineering.salesforce.com

Newsletter

One email every Tuesday

New guides, tool updates, and the release-note changes that break things.

No spam. Unsubscribe in one click.

Comments

Loading comments...

Leave a Comment