Summary
Zeplin does not have exposure to this vulnerability.
Background
Between August 8 and August 18 2025, a vulnerability in a popular integration for Salesforce, resulted in widespread data theft from Salesforce customer instances. Customers of Zeplin rightly ask if Zeplin was vulnerable to this issue.
Zeplin Exposure
Although Zeplin uses Salesforce as a vendor, Zeplin does not use Salesloft Drift, and therefore there is no risk of exposure to this vulnerability through Zeplin.
Zeplin facilitates integrations with other service providers (a list of which is available at zeplin.io/subprocessors). An investigation of all vendors with any likelihood of access to our Salesforce instance has verified no vendor is or was exposed to this vulnerability.
Updates
This bulletin was last updated on 5 September 2025.
New information will be updated here if and when we discover more.