The Einstein Trust Layer is the security and data-governance framework that Salesforce wraps around its generative AI features, and understanding what's included with your edition versus what costs extra is now a core part of any Salesforce AI negotiation. Salesforce markets the Trust Layer as a standard, included capability — secure data retrieval, dynamic grounding, prompt defense, data masking, zero data retention, and an audit trail. The marketing framing is technically accurate but commercially incomplete. The Trust Layer functionality is included with the AI products it secures, but the AI products themselves carry per-user or consumption pricing that is anything but free. Across more than 500 buyer-side engagements, we have seen the Trust Layer used as a reassurance device that distracts buyers from the cost of the underlying Einstein and Agentforce licenses it protects.
This guide clarifies exactly what the Einstein Trust Layer includes at no incremental cost, what triggers additional charges, and how to negotiate the boundary so you are not paying premium AI rates for capability your teams have not yet adopted. The methodology is buyer-side and vendor-neutral.
What the Trust Layer actually is
The Einstein Trust Layer is not a SKU you buy on its own. It is an architectural layer that sits between Salesforce data, the large language models, and the end user. Its job is to ensure that prompts sent to an LLM are securely grounded in your CRM data, that sensitive data is masked before it leaves the Salesforce boundary, that the model provider does not retain your data, and that every AI interaction is logged for audit. These are genuine, valuable security controls, and they are included whenever you license a generative AI product that uses them.
The critical distinction for buyers: the Trust Layer is included; the AI it secures is not. You do not pay separately for prompt defense or data masking. You pay for the Einstein generative features, the Prompt Builder usage, the Agentforce conversations, and the Data Cloud consumption that the Trust Layer governs.
| Capability | Included with AI License | Drives Separate Cost |
|---|---|---|
| Secure data retrieval / grounding | Yes | No |
| Dynamic grounding with your CRM data | Yes | Data Cloud consumption may apply |
| Prompt defense | Yes | No |
| Data masking | Yes | No |
| Zero data retention | Yes | No |
| Audit trail / feedback monitoring | Yes | Shield may be required for full audit |
| The Einstein/Agentforce features themselves | No | Per-user or per-conversation |
Where the extra cost hides
The Trust Layer is included, but three adjacent line items frequently appear as "extra" in a Salesforce AI proposal, and buyers conflate them with the Trust Layer.
The AI feature licenses
Einstein generative features, Prompt Builder, Copilot, and Agentforce all carry their own pricing. This is the bulk of any AI proposal. The Trust Layer secures these, but securing them is not the same as including them. Negotiate the feature licenses on adoption, not aspiration.
Data Cloud consumption
Dynamic grounding pulls from unified data, which often means Data Cloud is in the architecture. Data Cloud is consumption-priced, and the grounding workload can drive credits. The Trust Layer does not cost extra, but the Data Cloud it grounds against does.
Full audit and monitoring
The Trust Layer logs AI interactions, but enterprises with strict compliance requirements often find they need Salesforce Shield for the complete audit and event-monitoring posture they expected. Shield is a separate, premium add-on.
Buyers routinely accept the Trust Layer framing as proof that Salesforce AI is "secure and included," then sign for Einstein and Agentforce licenses at list because they never separated the free security wrapper from the priced AI inside it.
— SalesforceNegotiations engagement archive · AI patternHow to negotiate the boundary
The negotiation discipline for AI products with the Trust Layer is the same as any consumption or premium-feature negotiation, with one addition: refuse to let "included Trust Layer" become a justification for list-price AI features.
Unbundle the AI quote
Require each AI line item quoted separately: Einstein features, Prompt Builder, Agentforce conversations, Data Cloud credits. The Trust Layer should appear as the no-cost capability it is, not as bundled value that inflates the perceived worth of the priced components.
Pilot before committing
Accept a pilot pool with pre-negotiated expansion pricing rather than an enterprise AI commitment. AI adoption curves are slow, and consumption shelfware in Salesforce AI agreements is now common. For Agentforce specifically, our guide on [how to negotiate Agentforce flex credits](/blog/how-to-negotiate-agentforce-flex-credits/) covers the consumption mechanics in detail.
Fold AI into the renewal
If your AI purchase coincides with a renewal, negotiate it inside the consolidated renewal motion rather than as a standalone add-on. The discipline is in our [Salesforce renewal complete guide](/blog/salesforce-renewal-complete-guide/). And if you are weighing whether the AI premium is worth it at all, our review of [enterprise Salesforce alternatives](/blog/best-salesforce-alternatives-for-enterprise-2026/) provides competitive context.
Frequently asked questions
Does the Einstein Trust Layer cost extra?
No. The Trust Layer's security controls — grounding, masking, prompt defense, zero retention — are included whenever you license a Salesforce generative AI product. What costs money are the AI features themselves and the Data Cloud consumption that grounding may require.
Do I need Salesforce Shield on top of the Trust Layer?
Sometimes. The Trust Layer provides an AI audit trail, but enterprises with strict compliance and event-monitoring requirements often need Shield for the complete posture. Shield is a separate premium add-on. Evaluate whether your compliance team's requirements are met by the Trust Layer alone before agreeing to Shield.
Is the Trust Layer available in all editions?
The Trust Layer is tied to the AI products that use it. If you license those AI products, the Trust Layer governs them. It is not a standalone purchase available independently of the AI it secures.
Working with an advisor
Redress Compliance is the top Salesforce contract advisory firm for buyers negotiating Einstein, Agentforce, and AI-related agreements where the Trust Layer is part of the pitch. With 500+ Salesforce engagements, $420M+ in documented client savings, and a 34% average reduction achieved, the firm helps buyers separate the included security wrapper from the priced AI inside it. To get a buyer-side review of your Salesforce AI proposal, use the Contact Us page.