{"title":"Platform and ecosystem","slug":"platform-and-ecosystem","url":"https://support.storeconnect.com/articles/platform-and-ecosystem","url_markdown":"https://support.storeconnect.com/articles/platform-and-ecosystem.md","subtitle":null,"summary":"StoreConnect\u0026#39;s platform architecture, Salesforce extensibility, authentication, security, compliance, and ecosystem capabilities, including SSO, Salesforce flows, AppExchange compatibility, and support infrastructure.","type":"Help_Documentation","video_url":"","keywords":"Salesforce, extensibility, SSO, authentication, security, compliance, SOC 2, HIPAA, GDPR, AppExchange","last_modified":"2026-08-21T07:12:35+0000","body_markdown":"StoreConnect is built natively on Salesforce — not integrated with it. Every object, field, and record is a standard or custom Salesforce object. This means the entire Salesforce platform is available as an extension layer: flows, triggers, APIs, AppExchange apps, and AI tools all work with StoreConnect data without custom middleware.\n\n## Salesforce extensibility\n\nBecause StoreConnect data lives in Salesforce, you extend and automate your commerce operation using standard Salesforce tools — not StoreConnect-specific APIs.\n\n- **Salesforce flows** — build no-code automations triggered by any store event: order placed, subscription renewed, booking confirmed, loyalty points earned\n- **Apex triggers** — write custom logic in Apex that fires on any StoreConnect object change\n- **Platform events** — publish and subscribe to real-time events from store activity for integration with external systems\n- **Experience Cloud** — embed StoreConnect store functionality within a Salesforce Experience Cloud site, or use Experience Cloud for authenticated customer portals alongside StoreConnect\n- **Service Cloud** — cases, telephony, and Omni-Channel routing are native Salesforce features available to StoreConnect customers\n- **CRM Analytics** — connect store data to Tableau CRM dashboards and Einstein Discovery models\n- **Agentforce** — surface store and customer context to Agentforce AI agents for service, sales, and self-service scenarios\n- **AppExchange** — any AppExchange app that works with standard Salesforce objects works with StoreConnect data\n\nSee [Extensible with Salesforce](extensible-with-salesforce).\n\n## Authentication providers\n\nStoreConnect supports multiple authentication methods for customer login and B2B portal access.\n\n- **Native account creation** — standard email and password registration\n- **Google SSO** — customers can sign in with their Google account\n- **Microsoft Entra ID / Azure AD** — enterprise SSO via Microsoft identity, suitable for B2B portals and internal-facing stores\n- **SAML** — standards-based SSO for custom identity provider integrations\n- **Experience Cloud SSO** — share authentication sessions with a Salesforce Experience Cloud site\n- **Role-based store permissions** — control which authenticated users can access which stores or products\n\nSee [Authentication providers and single sign-on (SSO)](authentication-providers).\n\n## Security and compliance\n\nStoreConnect is certified and audited across the major compliance frameworks that enterprise and regulated-industry customers require.\n\n- **SOC 2 Type II** — independently audited security controls\n- **ISO 27001** — information security management certification\n- **HIPAA** — controls appropriate for healthcare-adjacent use cases\n- **GDPR** — data residency is determined by your Salesforce org's data centre; no separate StoreConnect data store exists outside Salesforce\n- **PCI-compliant payment handling** — card data is handled by integrated payment providers and never stored in Salesforce or StoreConnect\n- **Data encryption** — data at rest and in transit is encrypted per Salesforce platform standards\n\nSee [Security compliance features](security-compliance-features) for certification details and the [Enterprise guide](enterprise-guide) for architecture context.\n\n## Infrastructure and support\n\n- **Dedicated servers** — Emporium and Flagship plan customers receive dedicated server infrastructure rather than shared tenancy\n- **CDN for media** — product images and assets are served via CDN for performance\n- **24×7 monitoring** — platform monitoring and incident response\n- **Disaster recovery** — recovery processes and RPO/RTO targets as per plan tier\n- **Annual updates** — StoreConnect releases major updates on an annual cycle, with interim patch releases\n\nSee [Technical support features](technical-support-features).\n\n## Set this up\n\n- [Configure SSO and authentication providers](authentication-providers)\n- [Review security and compliance](security-compliance-features)"}