---
isPublished: true
template: "marketing.peb"
title: "Trust Center"
displayName: "Trust Center"
description: "Security, data handling, AI governance, compliance policies, and assurance evidence for iDialogue."
category: "trust"
contentType: "overview"
audience: "end-user"
tags: "trust,security,privacy,ai-governance,salesforce,compliance"
section: "trust"
seoTitle: "iDialogue Trust Center"
seoDescription: "Review how iDialogue protects Salesforce document generation and file-understanding workflows, governs AI agents, and shares assurance evidence."
---

<div class="trust-portal">

<section class="trust-hero" aria-labelledby="trust-center-title">
  <p class="trust-status">Security, governance, and assurance for iDialogue</p>
  <h1 id="trust-center-title">Enterprise trust for AI-powered Salesforce workflows</h1>
  <p>iDialogue helps organizations securely use AI to <strong>generate documents</strong>, <strong>understand files</strong>, and automate Salesforce workflows. Explore how we protect customer data, govern AI agents, control access, and validate our security practices.</p>
  <p><a href="#three-trust-pillars">Explore trust and security</a> or <a href="#functional-areas">browse a functional area</a>.</p>
</section>

<div class="trust-card-grid trust-card-grid--two" aria-label="Product journeys">
  <article class="trust-card">
    <h2 id="generate-documents">Generate documents</h2>
    <p>Turn trusted Salesforce data and approved templates into proposals, agreements, handoff documents, and customer Experiences, with controls around data access, AI processing, human review, and delivery.</p>
    <p><a href="/trust/security-data-handling.html#file-and-agent-data-flow">Review the document data flow</a></p>
  </article>
  <article class="trust-card">
    <h2 id="understand-files">Understand files</h2>
    <p>Use AI to extract, summarize, classify, and act on information in Salesforce Files, with configurable controls for processing, agent actions, validation, and Salesforce writeback.</p>
    <p><a href="/trust/ai-agent-governance.html#governed-workflow-examples">Review governed file workflows</a></p>
  </article>
</div>

<h2 id="start-with-your-role">Start with your role</h2>

<div class="trust-role-grid">
  <article class="trust-role-card">
    <h3>Business or Salesforce user</h3>
    <p>Understand what AI agents can do, where human review fits, and what happens before Salesforce data or customer-facing content changes.</p>
    <p><a href="/trust/ai-agent-governance.html#authority-and-approvals">Review authority and approvals</a></p>
  </article>
  <article class="trust-role-card">
    <h3>Salesforce Admin</h3>
    <p>Review how Salesforce identity, permissions, Connections, agent tools, file workflows, and sharing controls are configured.</p>
    <p><a href="/trust/security-data-handling.html#salesforce-api-integration">Review Salesforce API integration</a></p>
  </article>
  <article class="trust-role-card">
    <h3>IT, security, or CISO</h3>
    <p>Follow customer data through processing, storage, retention, external providers, access controls, and available assurance evidence.</p>
    <p><a href="/trust/security-data-handling.html#data-lifecycle">Review the data lifecycle</a></p>
  </article>
  <article class="trust-role-card">
    <h3>Procurement, Legal, or Compliance</h3>
    <p>Review security policies, data-processing practices, contractual safeguards, third-party providers, and available assurance materials.</p>
    <p><a href="/trust/compliance/index.html#documents-and-evidence">Review policies and evidence</a></p>
  </article>
</div>

<h2 id="functional-areas">Explore trust and security</h2>

<div class="trust-card-grid trust-grid--four">
  <article class="trust-card">
    <h3><a href="/trust/compliance/index.html#salesforce-security-review">Salesforce Security Review</a></h3>
    <p>Review the scope and evidence for iDialogue's successful AppExchange Security Review.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/security-data-handling.html#salesforce-api-integration">Salesforce API Integration</a></h3>
    <p>Understand Salesforce identity, OAuth, workflow context, permissions, and customer-configured access boundaries.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/ai-agent-governance.html#openai-integration">OpenAI Integration</a></h3>
    <p>Review how iDialogue uses OpenAI, including API credentials, data processing, storage behavior, and customer configuration options.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/security-data-handling.html#connections">Connections</a></h3>
    <p>Control which external services are connected and which approved agent skills are authorized to use them.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/ai-agent-governance.html#authority-and-approvals">Agent Authority &amp; Approval</a></h3>
    <p>Control agent capabilities through run context, enabled tools, connection permissions, approval requirements, and audit records.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/security-data-handling.html#data-lifecycle">Data Lifecycle</a></h3>
    <p>Understand how transient context, files, generated outputs, transcripts, memory, logs, and billing records are handled.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/security-data-handling.html#sharing-and-access">Sharing, Rooms &amp; Publishing</a></h3>
    <p>Understand how access is controlled for private customer Rooms, shared content, and deliberately public publishing.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/compliance/index.html#documents-and-evidence">Policies &amp; Evidence</a></h3>
    <p>Access security and privacy policies, Salesforce review evidence, scanning results, and other assurance materials.</p>
  </article>
</div>

<h2 id="security-model">Security model</h2>

<figure class="trust-diagram">
  <img src="/assets/img/trust/security-model.svg" width="1280" height="820" alt="Layered iDialogue security model connecting a Salesforce user and configured Salesforce org to iDialogue workflow controls, selected processing providers, stored artifacts, and audit records." />
  <figcaption>iDialogue uses layered controls across Salesforce, workflow configuration, AI providers, storage, sharing, and human review. Administrators control the connections, data context, agent capabilities, and approval requirements available to each workflow.</figcaption>
</figure>

<div class="trust-callout trust-callout--qualified">
  <strong>Security follows the workflow.</strong> Different iDialogue features may process selected Salesforce data, files, conversation state, or generated artifacts. Our Trust Center documents those data flows so customers can evaluate each deployment based on how it is actually configured and used.
</div>

<h2 id="three-trust-pillars">Three trust pillars</h2>

<div class="trust-card-grid">
  <article class="trust-card">
    <h3><a href="/trust/security-data-handling.html">Security &amp; Data Handling</a></h3>
    <p>Understand Salesforce and file data flows, encryption, retention, storage, Connections, sharing controls, and subprocessors.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/ai-agent-governance.html">AI &amp; Agent Governance</a></h3>
    <p>Review how agent capabilities, tools, approvals, provider controls, transcripts, usage, and auditability are governed.</p>
  </article>
  <article class="trust-card">
    <h3><a href="/trust/compliance/index.html">Compliance &amp; Policies</a></h3>
    <p>Access public policies, contractual safeguards, Salesforce Security Review information, vulnerability evidence, and other assurance materials.</p>
  </article>
</div>

<h2 id="documents-and-evidence">Documents and evidence</h2>

<div class="trust-document-grid trust-document-grid--two">
  <article class="trust-document-card">
    <h3>Publicly available</h3>
    <ul>
      <li><a href="/trust/compliance/privacy-data-protection.html">Privacy &amp; Data Protection Policy</a></li>
      <li><a href="/trust/compliance/data-retention.html">Data Retention Policy</a></li>
      <li><a href="/trust/compliance/encryption.html">Encryption Policy</a></li>
      <li><a href="/trust/compliance/vulnerability-management.html">Vulnerability Management Policy</a></li>
      <li><a href="/trust/compliance/risk-assessment.html">Risk Assessment Policy</a></li>
      <li><a href="/trust/compliance/third-party-security.html">Third-Party Security Policy</a></li>
      <li><a href="/trust/compliance/openai-data-processing-addendum.html">OpenAI Data Processing Addendum summary</a></li>
    </ul>
  </article>
  <article class="trust-document-card">
    <h3>Available by request or under NDA</h3>
    <ul>
      <li>Detailed architecture and endpoint diagrams</li>
      <li>Detailed vulnerability scan findings and remediation context</li>
      <li>Security questionnaires and customer-specific data-flow reviews</li>
      <li>Additional assurance materials containing sensitive operational details</li>
    </ul>
    <p>Request security documentation at <a href="mailto:support@idialogue.app">support@idialogue.app</a>.</p>
  </article>
</div>

<h2 id="frequently-asked-questions">Frequently asked questions</h2>

<div class="trust-faq">
  <details>
    <summary>What Salesforce data leaves Salesforce when a document or file workflow runs?</summary>
    <p>iDialogue sends only the context required by the configured feature or workflow. Depending on the workflow, this may include selected record fields, instructions, files, or prior conversation state. Processing may occur within iDialogue services and configured providers outside Salesforce. See the <a href="/trust/security-data-handling.html#file-and-agent-data-flow">file and agent data flow</a>.</p>
  </details>
  <details>
    <summary>Which Salesforce identity and permissions apply?</summary>
    <p>Server-side Salesforce access is principally controlled by the configured Salesforce connection or integration identity. Enabled tools and workflow configuration provide additional boundaries. Because external workflows may use an integration identity rather than automatically reproducing the initiating user's row-level access and field-level security, customers should review the identity and permissions configured for each workflow. See <a href="/trust/security-data-handling.html#salesforce-api-integration">Salesforce API Integration</a>.</p>
  </details>
  <details>
    <summary>What did the April 9, 2025 Salesforce Security Review cover?</summary>
    <p>The iDialogue v2.19.0 managed package successfully completed Salesforce's AppExchange Security Review on April 9, 2025. The review provides independent assurance for the package and submission evaluated by Salesforce. Hosted services, later releases, customer configurations, and third-party providers may have separate security considerations. See <a href="/trust/compliance/index.html#salesforce-security-review">review details</a>.</p>
  </details>
  <details>
    <summary>Does OpenAI train on API data, and how is stored state retained?</summary>
    <p>OpenAI states that API data is not used to train its models unless the API customer opts in. Current reviewed iDialogue Responses API workflows use <code>store=true</code> where required to support threaded conversations and background work. OpenAI's current documentation states that stored Responses application state is retained for at least 30 days. Other data classes, including abuse-monitoring logs, uploaded files, conversations, and optional sharing programs, may have different controls and retention behavior. See <a href="/trust/ai-agent-governance.html#provider-data-controls">provider data controls</a>.</p>
  </details>
  <details>
    <summary>Can a customer use its own OpenAI API key?</summary>
    <p>Yes. Customer-provided OpenAI API keys are supported for approved deployments and can be associated with the customer's organization in iDialogue. This gives the customer control over the provider account and provider-level administration. iDialogue workflow behavior, transcript handling, request-level storage settings, and provider retention should still be reviewed separately. See the <a href="/connections/openai.html">OpenAI Connection</a>.</p>
  </details>
  <details>
    <summary>What can an agent read or change, and when is approval required?</summary>
    <p>An agent's authority is determined by its run context, enabled skills and tools, Salesforce or external-service Connections, supplied data, and workflow configuration. Delete operations are not offered through the current Salesforce data-manipulation tool. Human confirmation or review can be required before consequential actions, with the exact approval point determined by the workflow. See <a href="/trust/ai-agent-governance.html#authority-and-approvals">authority and approvals</a>.</p>
  </details>
  <details>
    <summary>Which Connections can an agent use?</summary>
    <p>Connections make approved external services available to iDialogue workflows. A service appearing in the Connections catalog does not mean it is configured, authorized, or used within a particular customer organization. Administrators can review configured Connections and the skills enabled for each agent. See the <a href="/connections/index.html">Connections catalog</a>.</p>
  </details>
  <details>
    <summary>Where are uploaded and generated files stored, and who can access Rooms or public content?</summary>
    <p>Depending on the feature, iDialogue can read Salesforce Files, temporarily process file content, and store generated or shared artifacts in iDialogue-managed storage. Private customer Rooms and deliberately public publishing use different access models. Customers should review membership, invitation, domain, sharing, and publication settings for the specific Experience. See <a href="/trust/security-data-handling.html#sharing-and-access">sharing and access</a>.</p>
  </details>
  <details>
    <summary>What transcript, tool, usage, and audit information is retained?</summary>
    <p>Threaded agent workflows can retain user and assistant messages, model information, tool-call details, token usage, and credit records to support conversation continuity, administration, billing, and investigation. Operational and security logs are maintained separately. Retention and access controls should be evaluated by data class and applicable contract. See <a href="/trust/ai-agent-governance.html#transcripts-and-audit">transcripts and audit</a>.</p>
  </details>
  <details>
    <summary>How are credits, rate limits, overages, and background agents controlled?</summary>
    <p>iDialogue meters agent and processing activity using credits and records usage for billing and operations. Provider rate limits and model capacity are managed separately and may change over time. Higher-volume or governance-sensitive deployments may use customer-provided provider credentials and customer-managed provider limits. Background agents can continue processing after an interactive request, so customers should configure appropriate budgets, workflow permissions, and exception handling. See <a href="/trust/ai-agent-governance.html#usage-and-cost-controls">usage and cost controls</a>.</p>
  </details>
</div>

<section class="trust-callout" aria-labelledby="trust-review-title">
  <h2 id="trust-review-title">Planning an enterprise deployment?</h2>
  <p>Our team can provide a customer-specific security and data-flow review covering Salesforce access, selected fields and files, AI providers, agent capabilities, storage, sharing, and approval controls. Contact <a href="mailto:support@idialogue.app">support@idialogue.app</a>.</p>
</section>

</div>