We understand that data security in case management software is one of the most important things you consider when choosing a system to store your client data. As a GDPR compliant case management system, In-Form is built to meet that responsibility from the ground up .That’s why In-Form takes security seriously and it’s also why we want to keep you updated about the changes happening at the platform level.
Because In-Form is built on Salesforce, we benefit from all the security investment Salesforce puts into the platform In-Form sits on. Throughout 2026, Salesforce has been rolling out a significant set of Salesforce security updates designed to cut down the risk of phishing attacks, data theft and account takeovers. Some of these changes happen quietly in the background. Others will show up as something new in your day-to-day In-Form login, such as a prompt to set up an extra security step.
We’ve pulled together what each update actually is and what it means for you as an In-Form user.
Locking the door: stopping suspicious logins before they happen
These Salesforce security updates for 2026 start with three changes focused on stopping suspicious logins before they happen
Email Domain Verification
Salesforce now checks that any email sent from Salesforce comes from a properly verified sending domain, rather than delivering by default. If a domain hasn’t been verified, the email simply won’t send. This closes a loophole that attackers could otherwise use to send convincing, spoofed emails that look like they come from a trusted organisation.
What it means for you: This is largely a behind-the-scenes safeguard. If your organisation uses In-Form to send automated emails or notifications, the In-Form support team makes sure your sending domain is verified, so you shouldn’t notice any disruption.
Preventing Connections from Anonymising VPNs, Proxies and High-Risk IP Addresses
Attackers often try to hide their tracks by routing their login attempts through anonymising VPNs or proxy services. Salesforce now automatically freezes any account it detects connecting this way through apps or system integrations and notifies your organisation’s admin so they can investigate.
What it means for you: If you personally use a VPN for privacy or work reasons, it’s worth checking with your organisation’s admin whether that could trigger a temporary account freeze, genuine users occasionally get caught by this and it’s a quick fix for an admin to sort out. For everyone else, this is simply another layer working quietly to keep unauthorised users out of your organisation’s data.
Extended Login Anomaly Detections and Containment
It’s a small inconvenience in exchange for much stronger protection and it’s part of what keeps In-Form a GDPR compliant case management system your organisation can rely on.
Salesforce now uses AI-driven monitoring to spot unusual login behaviour, for instance a login pattern that looks very different from how a particular user normally logs in. When something significant is flagged, the account is automatically frozen, access tokens are revoked and the organisation’s admin is notified.
What it means for you: This is another safeguard that mostly works invisibly. If your own login is ever flagged as unusual (if you’re logging in from an unfamiliar location or device), you may be asked to reset your password once your admin has reviewed and confirmed it’s genuinely you. It’s a small inconvenience in exchange for much stronger protection against accounts being hijacked.
Proving it's really you: sign-in requirements and data security in case management software
Phishing-Resistant MFA Enforcement for Privileged Users, Including Admins
If you’re a system administrator, or hold certain elevated permissions in your In-Form setup, Salesforce now requires you to use “phishing-resistant” multi-factor authentication (MFA) to log in. In practice, this means using a passkey, either a built-in device authenticator (like Face ID, Touch ID or Windows Hello) or a physical security key, rather than a code from an authenticator app, since those traditional codes can still be intercepted by a sophisticated phishing attempt.
What it means for you: If you’re an admin for your organisation’s In-Form system, you’ll be prompted to set up a passkey the next time you log in, if you haven’t already. It’s a one-off setup that takes a couple of minutes and makes your login both more secure and in many cases, faster than typing a password.
MFA Enforcement for All Users
Alongside the stricter requirement for admins, Salesforce now requires every user to have some form of MFA enabled to log in, whether that’s a passkey or a standard authenticator app. This has technically been best practice for a while, but Salesforce is now enforcing it for everyone, every time.
What it means for you: If you haven’t already set up MFA on your account, you’ll be asked to register a method the next time you log in. Once it’s set up, it just becomes part of your normal login, Salesforce will ask for that second step alongside your username and password (or in place of a password, if you choose a passkey).
Extra checks when it matters most: reporting exports and unusual behaviour
Step-up Auth for Report Activities
Because pulling a report is one of the easiest ways for someone to extract a large amount of client data in one go, Salesforce now periodically asks users to re-verify their identity specifically when exporting reports, even if they’re already logged in. By default, you’ll be re-prompted after two hours have passed since your last verification.
What it means for you: If you regularly pull reports from In-Form- say, for outcomes tracking, funder reporting, or case reviews, you may occasionally be asked to verify your identity again before you can export, even mid-session. It’s a small extra step that reflects what good data security in case management software should look like: protecting your clients’ data even if your account was ever compromised without your knowledge.
Step-up Authentication for Anomalous Behaviour
On top of the time-based check above, Salesforce also uses machine learning to spot when someone’s report activity looks unusual for them personally, for example, exporting a much larger volume of records than they typically would. When that happens, the user is prompted for an extra identity check before the export is allowed to go ahead.
What it means for you: Most of the time, you won’t notice this at all, it only kicks in when your activity looks genuinely different from your normal pattern. If you are prompted, it’s simply Salesforce double-checking that it’s really you before letting a large or unusual data export through.
For organisations using Salesforce Shield
Transaction Security Policy Enhancements
For organisations that need to demonstrate the highest level of assurance to funders or regulators, Salesforce Shield adds another layer to keeping In-Form a GDPR compliant case management system. For the smaller number of organisations using Salesforce Shield (an advanced add-on for monitoring and encryption), Salesforce has introduced a default policy that requires step-up verification whenever a report export exceeds 10,000 records in one go. This turns what used to be passive monitoring into active prevention, stopping a large, suspicious export before the data ever leaves the organisation, rather than just logging it afterwards.
What it means for you: This is only if your organisation has Salesforce Shield in place. If that’s you, your admin may already have seen this policy appear and can adjust the threshold if needed. For everyone else, it’s worth knowing that this level of protection exists as an option, should your organisation’s needs ever call for it.
Data security in case management software: what should you do now?
Most of these changes either work quietly in the background or simply add a short, one-off setup step to your login.
Our advice:
- If you’re prompted to set up a passkey or MFA method, go ahead and do it. It takes a couple of minutes and it’s the single most effective thing you can do to protect your account.
- If you’re a system administrator for your organisation’s In-Form system, keep an eye out for admin notifications about frozen accounts or verification prompts, since you may need to review and unfreeze genuine users occasionally.
- If anything about your login experience changes unexpectedly and you’re not sure why, get in touch with us, we’re happy to help you figure out whether it’s one of these updates at play.
Contact us
If you’d like more information on how In-Form keeps your data safe, or if you’d like support working through any of these changes for your organisation, please raise a support case.
In the meantime, Salesforce Trust is a great place to find out more about the data security measures Salesforce has in place, and Salesforce’s own Security-Related Product Updates page has the full technical detail and rollout timelines for each change above.


