---
isPublished: true
template: "page.peb"
title: "Third-Party Security Policy"
displayName: "Third-Party Security Policy"
description: "Public due diligence, contracting, access, monitoring, and offboarding principles for iDialogue service providers and Connections."
category: "trust"
contentType: "policy"
audience: "end-user"
tags: "trust,policy,third-party-security,vendors,subprocessors,connections"
section: "trust"
effectiveDate: "2026-05-22"
lastReviewed: "2026-05-22"
owner: "Security and Privacy"
contact: "support@idialogue.app"
seoTitle: "iDialogue Third-Party Security Policy"
seoDescription: "Review how Pacific Apps evaluates and governs infrastructure, processing providers, subprocessors, and optional Connections."
---

## Third-Party Security Policy

**Effective date:** May 22, 2026  
**Last reviewed:** May 22, 2026  
**Policy owner:** Security and Privacy  
**Entity:** Pacific Apps, Inc., provider of iDialogue  
**Contact:** [support@idialogue.app](mailto:support@idialogue.app)

<h2 id="purpose">Purpose</h2>

Pacific Apps, Inc. uses infrastructure, AI, payment, communications, data, development, and other service providers to operate and extend iDialogue. This policy defines requirements for evaluating, contracting with, configuring, monitoring, and offboarding third-party providers based on the risk and access associated with each relationship.

<h2 id="classification">Risk-based provider classification</h2>

Third-party providers are evaluated according to the risk, data, and capabilities involved in the relationship, including:

- the customer or personal data the provider receives;
- whether data is stored or processed transiently;
- access to credentials, production systems, or customer-facing actions;
- security, privacy, availability, financial, legal, and concentration risk;
- whether the provider is part of the core iDialogue service or an optional customer-enabled Connection; and
- whether the customer maintains its own provider account, contract, credentials, or administrative controls.

<strong>A Connection appearing in the iDialogue catalog does not mean it is configured for or used by a particular customer.</strong>

<h2 id="due-diligence">Due diligence</h2>

Provider due diligence is proportionate to the risk and role of the service. Reviews may consider:

- security and privacy documentation;
- Data Processing Addenda and contractual terms;
- architecture, hosting, and data location;
- retention and deletion practices;
- identity and access controls;
- encryption and key-management practices;
- incident-response obligations;
- business continuity and resilience;
- independent assessments or certifications where available; and
- material vulnerability or security history.

Assurance evidence is evaluated according to its scope, date, and applicability to the service being used. A provider's certification or security assessment does not automatically extend to iDialogue's configuration or a customer's workflow.

<h2 id="contractual-and-configuration-controls">Contractual and configuration controls</h2>

Depending on the provider's role and risk, Pacific Apps applies appropriate contractual and technical safeguards, which may include:

- confidentiality, privacy, security, incident, deletion, and subprocessor terms;
- least-privileged credentials and customer- or tenant-scoped configuration;
- restrictions on provider training and optional data-sharing or service-improvement programs;
- endpoint- or request-level retention controls;
- audit, termination, export, and deletion rights; and
- documented contingency or exit plans for material dependencies.

Pacific Apps and OpenAI entered into a Data Processing Addendum on July 9, 2023. See the [public summary and redacted executed agreement](/trust/compliance/openai-data-processing-addendum.html).

<h2 id="connections">Customer-enabled Connections</h2>

iDialogue Connections allow customers to authorize optional external services for specific workflows. Depending on the service, a Connection may use customer-controlled OAuth authorization or credentials, or an iDialogue-managed service.

Customers control which optional Connections they authorize and should review:

- credential and authorization scope;
- enabled agent skills and tools;
- data sent to the service;
- permitted actions;
- usage and rate limits;
- cost and billing implications; and
- offboarding requirements.

The [Connections catalog](/connections/index.html) describes services that can be made available through iDialogue. It is not a universal list of subprocessors used for every customer.

<h2 id="monitoring-and-change">Monitoring and change</h2>

Material providers are reassessed when changes to service scope, data use, contractual terms, ownership, hosting location, technical integration, security incidents, or assurance evidence materially affect the risk of the relationship.

Identified risks are assigned an owner and treated according to the [Risk Assessment Policy](/trust/compliance/risk-assessment.html).

<h2 id="offboarding">Offboarding</h2>

Provider offboarding includes, as applicable:

- revoking credentials, tokens, and access;
- disabling or replacing dependent workflows;
- exporting or migrating required customer or operational data;
- requesting supported deletion from the provider;
- preserving records required for security, legal, financial, or contractual purposes; and
- confirming ownership and treatment of remaining dependencies.

Material provider transitions should include an identified owner and continuity or migration plan where service interruption could affect customers.

<h2 id="provider-information">Provider and subprocessor information</h2>

Customers can request a current provider or subprocessor review applicable to their iDialogue deployment. Available information may include provider role, data processed, applicable Connections, contractual safeguards, and relevant security documentation.

Some architecture, security, or operational details may be provided through a security questionnaire, customer agreement, or under NDA.

Contact [support@idialogue.app](mailto:support@idialogue.app).

## Related information

- [Security &amp; Data Handling: Providers and subprocessors](/trust/security-data-handling.html#providers-and-subprocessors)
- [OpenAI Data Processing Addendum](/trust/compliance/openai-data-processing-addendum.html)
- [Risk Assessment Policy](/trust/compliance/risk-assessment.html)