Encryption Policy

Encryption Policy

Effective date: May 22, 2026
Last reviewed: May 22, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app

Purpose

This policy defines iDialogue requirements for protecting data in transit and at rest, including transport security, storage encryption, credential protection, and key management. Specific implementations may vary by service, provider, data classification, and customer configuration.

Data in transit

Pacific Apps requires encrypted transport for supported production web and API connections. Certificate lifecycle, protocol configuration, and endpoint exposure are monitored and updated as platform and provider requirements change.

Customers are responsible for secure Salesforce connected-app settings, trusted network or IP policies they choose to apply, supported browsers and clients, and secure handling of downloaded or exported content.

Data at rest

Production storage used for customer content, application state, logs, credentials, and backups is required to use encryption at rest appropriate to the service and data classification.

Approved implementations may include managed-service encryption, encrypted volumes, object-storage encryption, or other storage-specific controls.

Encryption algorithms, key ownership, rotation methods, and customer-managed-key availability vary by service and deployment. iDialogue does not make a universal claim that every data class uses the same encryption algorithm or customer-managed keys.

Credentials and secrets

  • API keys, OAuth tokens, signing material, and service credentials must not be embedded in prompts, public documentation, source-controlled configuration, or generated customer content.
  • Application access to secrets must be limited to required services and authorized operators.
  • Credentials must be revoked or rotated after suspected exposure, role change, provider transition, or another material risk event.
  • Customer-provided provider credentials are associated with the applicable customer configuration and should be provisioned with least privilege.

Key management

Key and certificate lifecycle controls include authorized creation, restricted access, secure storage, rotation or renewal, revocation, monitoring, and recovery.

Where managed cloud services provide encryption or certificate management, portions of this lifecycle operate under the provider's service controls.

Verification

Encryption controls are verified through applicable configuration reviews, certificate monitoring, platform and dependency updates, access reviews, point-in-time TLS testing, and incident investigation.

The public Qualys SSL Labs evidence represents the tested endpoint and date.

Exceptions

Any exception requires a documented owner, business justification, risk assessment, compensating control, approval, and review or expiration date.

Related information

Generated 2026-08-11T02:58:43.360735Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.