---
isPublished: true
template: "page.peb"
title: "Vulnerability Management Policy"
displayName: "Vulnerability Management Policy"
description: "Public vulnerability identification, prioritization, remediation, verification, and disclosure expectations for iDialogue."
category: "trust"
contentType: "policy"
audience: "end-user"
tags: "trust,policy,vulnerability-management,scanning,remediation"
section: "trust"
effectiveDate: "2026-05-22"
lastReviewed: "2026-05-22"
owner: "Security and Privacy"
contact: "support@idialogue.app"
seoTitle: "iDialogue Vulnerability Management Policy"
seoDescription: "Review how Pacific Apps identifies, prioritizes, remediates, verifies, and communicates vulnerabilities affecting iDialogue."
---

## Vulnerability Management Policy

**Effective date:** May 22, 2026  
**Last reviewed:** May 22, 2026  
**Policy owner:** Security and Privacy  
**Entity:** Pacific Apps, Inc., provider of iDialogue  
**Contact:** [support@idialogue.app](mailto:support@idialogue.app)

<h2 id="purpose">Purpose</h2>

Pacific Apps, Inc. maintains a risk-based vulnerability management program to identify, assess, prioritize, remediate, and verify vulnerabilities affecting iDialogue applications, Salesforce package code, dependencies, infrastructure, and externally reachable services.

<h2 id="sources">Identification sources</h2>

Vulnerabilities are identified through applicable sources including:

- secure development practices and code review;
- Salesforce submission and source-scanning processes;
- dependency, static, dynamic, passive, and configuration scanning;
- cloud, platform, and provider security advisories;
- operational monitoring and incident investigation;
- reports from customers, researchers, employees, and partners; and
- point-in-time transport and endpoint-security testing.

<strong>No single scanner or testing method is treated as complete coverage.</strong>

<h2 id="triage">Triage and prioritization</h2>

Findings are evaluated in context rather than prioritized solely by a scanner-assigned severity.

Triage considers:

- the affected component and deployment;
- exploitability and external exposure;
- privileges and required user interaction;
- confidentiality, integrity, availability, financial, and privacy impact;
- customer data and tenant-isolation implications;
- active exploitation and available compensating controls;
- vendor or dependency guidance; and
- operational risk associated with remediation.

<h2 id="remediation">Remediation</h2>

Validated findings are assigned an accountable owner and risk-based treatment.

Treatment may include:

- code or configuration changes;
- dependency updates;
- access restrictions;
- monitoring;
- compensating controls;
- provider remediation;
- documented risk acceptance; or
- service retirement.

Remediation timing is based on severity, exploitability, exposure, customer impact, available mitigations, and operational risk. Applicable contractual commitments are incorporated into remediation requirements.

<h2 id="verification">Verification and closure</h2>

A finding is closed only after appropriate verification or documented risk acceptance.

Verification may include focused testing, rescanning, code review, deployment validation, configuration review, or provider confirmation.

Repeated or systemic findings may result in changes to development practices, testing, architecture, monitoring, or provider governance.

<h2 id="disclosure">Reporting vulnerabilities</h2>

Suspected vulnerabilities should be reported privately to [support@idialogue.app](mailto:support@idialogue.app) with the affected service or endpoint, reproduction steps, observed behavior, and other information useful for investigation.

Researchers must not access data that does not belong to them, intentionally disrupt service, or publicly disclose exploitable details before Pacific Apps has had a reasonable opportunity to investigate and coordinate remediation.

Customer notification is provided as required by applicable law and contract when a confirmed security issue materially affects customer data or service.

<h2 id="public-evidence">Security testing and assurance evidence</h2>

The [Compliance &amp; Policies](/trust/compliance/index.html#assurance-evidence) page publishes scoped evidence from Salesforce source scanning, OWASP ZAP passive scanning, and Qualys TLS testing.

These artifacts provide point-in-time evidence for the tested code or endpoints. Point-in-time scanner results do not represent complete vulnerability coverage.

Detailed vulnerability findings, remediation information, and additional security evidence may be provided under NDA where appropriate.

## Related information

- [Risk Assessment Policy](/trust/compliance/risk-assessment.html)
- [Encryption Policy](/trust/compliance/encryption.html)
- [Compliance &amp; Policies](/trust/compliance/index.html)