MuleSoft has migrated to the Salesforce Edge Network to enhance the protection of our publicly available infrastructure from distributed denial of service (DDoS) and vulnerabilities while also lowering per-connection latency. The move improved detection and response while supporting the kinds of traffic that integration and API workloads often generate.
Why we improved our edge performance and security
Our goal was to raise the bar for the platforms and APIs that power your integrations and applications. DDoS attacks continue to evolve in size and technique, and application-layer and short-duration attacks make fast, accurate detection and mitigation essential.
We wanted better detection and response for customer-facing services, without sacrificing the ability to handle legitimate traffic that uses larger headers or less common request patterns.
Additionally, security and compliance requirements keep evolving to meet these challenges. PCI DSS 4.0 introduces updated controls for protecting cardholder data environments. Among them, requirement 6.4.2 calls for deploying a web application firewall (WAF) in front of public-facing web applications, configured to detect and prevent attacks going beyond DDoS to address patterns of malicious behavior at the application layer. Adopting Salesforce Edge allows us to align our edge and mitigation capabilities with these kinds of expectations, including WAF-style detection and protection for the traffic we serve.
What Salesforce Edge delivers
Salesforce Edge Network routes traffic through Salesforce’s global edge servers. For MuleSoft, that means Anypoint Platform and the critical services you depend on are secured and accelerated. The acceleration comes from the reduced round trip time when negotiating TCP and TLS. To accomplish this, your connection is routed to the closest Edge point of presence to your geographic region.
Many CDNs enforce strict limits on header size and request formatting. Integration and API traffic, especially with tokens, signed payloads, or custom headers can hit those limits and be rejected as invalid. Salesforce Edge supports larger header sizes and is more permissive about forwarding requests that are valid but nonstandard. That means fewer false rejections and a better experience for your integrations.
The mitigation service is built to detect and respond to volumetric and application layer attacks quickly. By routing traffic through a distributed edge, we improve our ability to identify and mitigate attacks before they impact availability and still allow legitimate traffic through.
The Trusted Perimeter processes an average of 39B requests for Mulesoft every week and has inspected and protected almost 1T requests so far. It has ensured that Mulesoft remains protected against L3/L4/L7 DDoS attacks while improving performance and reducing overall latency.
What this means for you
The services and APIs served through Mulesoft’s Anypoint platform now sit behind this distributed network edge and attack mitigation layer. We chose Salesforce Edge because it fits our commitment to trust and reliability. We will keep investing in edge and application security so you can focus on building and scaling your integrations.
For more on how we protect your data and our compliance posture, see the MuleSoft Trust Center.
Salesforce Edge Network for your org
Infrastructure protection is being enabled across all Salesforce orgs with the majority of orgs already protected. When your org routes through Edge Network, you get intelligent routing to the nearest Salesforce Edge point of presence location and reduced latency for globally distributed users. Static content can be cached at the edge for faster load times, and protocol optimizations help move data more efficiently across the backbone. If you’re running Salesforce with users around the world, Edge Network can improve both performance and reliability.




