---
isPublished: true
template: "page.peb"
title: "Compliance & Policies"
displayName: "Compliance & Policies"
description: "Public policies, contractual safeguards, Salesforce review evidence, security scanning evidence, and framework references for iDialogue."
category: "trust"
contentType: "overview"
audience: "legal"
tags: "trust,compliance,assurance,policies,salesforce-review,security-testing"
section: "trust"
seoTitle: "iDialogue Compliance and Policies"
seoDescription: "Access iDialogue public policies, OpenAI contractual information, Salesforce AppExchange review evidence, and point-in-time security test evidence."
---

<div class="trust-portal">

<section class="trust-hero" aria-labelledby="compliance-assurance-title">
  <p class="trust-status"><a href="/trust/index.html">Trust Center</a> · Compliance &amp; Policies</p>
  <h1 id="compliance-assurance-title">Security assurance you can verify</h1>
  <p>iDialogue publishes security and privacy policies, contractual safeguards, Salesforce review evidence, and point-in-time security testing so customers can evaluate the controls relevant to their deployment. Each artifact is presented with its applicable scope and date.</p>
</section>

<h2 id="compliance-posture">Compliance posture</h2>

Pacific Apps, Inc., provider of iDialogue, maintains a security and privacy program that combines documented policies, contractual safeguards, provider governance, operational controls, Salesforce marketplace review, and security testing.

Independent certifications or attestations are identified explicitly when applicable. Framework references on this page describe security and risk-management inputs and should not be interpreted as certifications.

<h2 id="salesforce-security-review">Salesforce Security Review</h2>

<figure class="trust-evidence-card">
  <img src="/assets/img/trust/evidence/salesforce-appexchange-security-review-passed-2025-04-09.png" loading="lazy" width="1334" height="883" alt="Salesforce AppExchange Security Review portal showing that the displayed iDialogue version 2.19.0 managed package submission passed and was approved April 9, 2025." />
  <figcaption><strong>Salesforce AppExchange Security Review, April 9, 2025.</strong> The displayed iDialogue v2.19.0 managed package successfully completed Salesforce's AppExchange Security Review. Review scope applies to the submitted package and version.</figcaption>
</figure>

The Salesforce Security Review provides meaningful assurance for the managed package submitted to Salesforce. Hosted iDialogue services, customer-specific Salesforce configuration, external providers, and later releases have their own security considerations and controls.

<h2 id="public-policies">Public policies</h2>

<div class="trust-document-grid">
  <article class="trust-document-card">
    <h3><a href="/trust/compliance/privacy-data-protection.html">Privacy &amp; Data Protection</a></h3>
    <p>How customer and personal data are processed, protected, and handled, including individual data requests.</p>
  </article>
  <article class="trust-document-card">
    <h3><a href="/trust/compliance/data-retention.html">Data Retention</a></h3>
    <p>How files, generated artifacts, transcripts, knowledge, logs, and financial records are retained and removed.</p>
  </article>
  <article class="trust-document-card">
    <h3><a href="/trust/compliance/encryption.html">Encryption</a></h3>
    <p>Transport, storage, credential, and key-management control objectives.</p>
  </article>
  <article class="trust-document-card">
    <h3><a href="/trust/compliance/vulnerability-management.html">Vulnerability Management</a></h3>
    <p>How security findings are identified, prioritized, remediated, verified, and disclosed.</p>
  </article>
  <article class="trust-document-card">
    <h3><a href="/trust/compliance/risk-assessment.html">Risk Assessment</a></h3>
    <p>How security risks are identified, assigned, treated, and reviewed over time.</p>
  </article>
  <article class="trust-document-card">
    <h3><a href="/trust/compliance/third-party-security.html">Third-Party Security</a></h3>
    <p>How providers are evaluated through due diligence, contractual safeguards, ongoing review, and offboarding.</p>
  </article>
</div>

<h2 id="contractual-safeguards">Contractual safeguards</h2>

Pacific Apps, Inc. and OpenAI entered into a Data Processing Addendum on July 9, 2023. A reviewed and redacted copy is available publicly, with sensitive execution and account-identifying information removed.

- [Read the OpenAI DPA summary](/trust/compliance/openai-data-processing-addendum.html)
- [Download the reviewed/redacted agreement](/assets/documents/trust/openai-data-processing-addendum-pacific-apps-openai-2023-07-09-redacted.pdf)

The DPA provides contractual data-protection safeguards. Current endpoint behavior and provider data controls are documented separately because they can evolve independently of the agreement.

<h2 id="assurance-evidence">Security testing and assurance evidence</h2>

<div class="trust-evidence-grid">
  <figure class="trust-evidence-card">
    <img src="/assets/img/trust/evidence/salesforce-forcecom-source-scanner-results-2025-02-18-redacted.png" loading="lazy" width="2266" height="2690" alt="Redacted Force.com Source Scanner results dated February 18, 2025, showing zero security issues and twelve code-quality issues." />
    <figcaption><strong>Force.com Source Scanner, February 18, 2025.</strong> The displayed scan reports 0 security issues and 12 code-quality issues. Sensitive identifiers and email information have been redacted.</figcaption>
  </figure>
  <figure class="trust-evidence-card">
    <img src="/assets/img/trust/evidence/qualys-ssl-labs-api-i-dialogue-com-grade-a-2026-08-10.png" loading="lazy" width="2158" height="724" alt="Qualys SSL Labs result for api.i-dialogue.com showing a grade A on August 10, 2026." />
    <figcaption><strong>Qualys SSL Labs, August 10, 2026.</strong> The tested api.i-dialogue.com endpoint received an A rating for its TLS configuration. Results apply to the tested endpoint and date.</figcaption>
  </figure>
  <figure class="trust-evidence-card">
    <img src="/assets/img/trust/evidence/zap-passive-scan-summary-2025-02-11.svg" loading="lazy" width="1200" height="620" alt="Sanitized OWASP ZAP passive scan summary dated February 11, 2025, showing zero high-risk alerts, five medium, three low, and three informational alerts." />
    <figcaption><strong>OWASP ZAP passive scan, February 11, 2025.</strong> The reviewed passive scan reported 0 High, 5 Medium, 3 Low, and 3 Informational alerts across staging.i-dialogue.com, api.idialogue.app, and api.i-dialogue.com. Detailed findings and remediation context are available under NDA.</figcaption>
  </figure>
</div>

Security findings are evaluated in the context of the affected endpoint, exploitability, and business impact. Detailed vulnerability findings and remediation context are available under NDA when appropriate.

<h2 id="framework-references">Security framework references</h2>

Pacific Apps uses the **NIST Cybersecurity Framework (CSF)** as an input to security policy and cybersecurity risk management.

The **NIST AI Risk Management Framework (AI RMF)** and **MITRE ATLAS** inform ongoing AI-risk and threat-modeling work.

These framework references do not represent certifications, attestations, or government approvals.

<h2 id="documents-and-evidence">Documents and evidence access</h2>

### Public assurance materials

- the six security and privacy policies on this page;
- the [Privacy Policy](/legal/privacy.html);
- the [OpenAI DPA summary and reviewed/redacted agreement](/trust/compliance/openai-data-processing-addendum.html);
- scoped screenshots and sanitized assurance evidence on this page; and
- feature-specific [Security &amp; Data Handling](/trust/security-data-handling.html) and [AI &amp; Agent Governance](/trust/ai-agent-governance.html) guidance.

### Additional materials for enterprise review

- detailed architecture and data-flow diagrams;
- detailed vulnerability findings and remediation context;
- security questionnaires and control evidence;
- customer-specific provider and subprocessor reviews;
- audit or penetration-test materials when available and appropriate to disclose; and
- other sensitive assurance materials relevant to the proposed deployment.

<h2 id="additional-assurance">Customer-specific security reviews</h2>

Enterprise deployments often require review of the exact Salesforce configuration and workflow rather than the platform in the abstract. iDialogue can provide a scoped review covering:

1. Salesforce objects, fields, files, and integration identity;
2. enabled agents, skills, tools, and Connections;
3. processing providers and request-level storage settings;
4. artifact, transcript, memory, log, and billing data classes;
5. Room, member, sharing, and public-publishing access;
6. retention and deletion requirements; and
7. evidence needed for procurement or security review.

<h2 id="vendor-governance">Vendor governance</h2>

Third-party providers are evaluated according to the data they process, the capabilities they provide, and their role in the iDialogue architecture. Reviews can include provider documentation, contractual safeguards, security controls, configuration, operational dependency, and offboarding requirements.

See the [Third-Party Security Policy](/trust/compliance/third-party-security.html) for additional information.

<section class="trust-callout" aria-labelledby="assurance-request-title">
  <h2 id="assurance-request-title">Need security documentation for your review?</h2>
  <p>We can provide architecture details, security questionnaires, customer-specific data-flow reviews, and additional assurance materials appropriate to your deployment. Sensitive materials may require an NDA. Contact <a href="mailto:support@idialogue.app">support@idialogue.app</a>.</p>
</section>

</div>