Compliance & Policies

Trust Center · Compliance & Policies

Security assurance you can verify

iDialogue publishes security and privacy policies, contractual safeguards, Salesforce review evidence, and point-in-time security testing so customers can evaluate the controls relevant to their deployment. Each artifact is presented with its applicable scope and date.

Compliance posture

Pacific Apps, Inc., provider of iDialogue, maintains a security and privacy program that combines documented policies, contractual safeguards, provider governance, operational controls, Salesforce marketplace review, and security testing.

Independent certifications or attestations are identified explicitly when applicable. Framework references on this page describe security and risk-management inputs and should not be interpreted as certifications.

Salesforce Security Review

Salesforce AppExchange Security Review portal showing that the displayed iDialogue version 2.19.0 managed package submission passed and was approved April 9, 2025.
Salesforce AppExchange Security Review, April 9, 2025. The displayed iDialogue v2.19.0 managed package successfully completed Salesforce's AppExchange Security Review. Review scope applies to the submitted package and version.

The Salesforce Security Review provides meaningful assurance for the managed package submitted to Salesforce. Hosted iDialogue services, customer-specific Salesforce configuration, external providers, and later releases have their own security considerations and controls.

Public policies

Privacy & Data Protection

How customer and personal data are processed, protected, and handled, including individual data requests.

Data Retention

How files, generated artifacts, transcripts, knowledge, logs, and financial records are retained and removed.

Encryption

Transport, storage, credential, and key-management control objectives.

Risk Assessment

How security risks are identified, assigned, treated, and reviewed over time.

Third-Party Security

How providers are evaluated through due diligence, contractual safeguards, ongoing review, and offboarding.

Contractual safeguards

Pacific Apps, Inc. and OpenAI entered into a Data Processing Addendum on July 9, 2023. A reviewed and redacted copy is available publicly, with sensitive execution and account-identifying information removed.

The DPA provides contractual data-protection safeguards. Current endpoint behavior and provider data controls are documented separately because they can evolve independently of the agreement.

Security testing and assurance evidence

Redacted Force.com Source Scanner results dated February 18, 2025, showing zero security issues and twelve code-quality issues.
Force.com Source Scanner, February 18, 2025. The displayed scan reports 0 security issues and 12 code-quality issues. Sensitive identifiers and email information have been redacted.
Qualys SSL Labs result for api.i-dialogue.com showing a grade A on August 10, 2026.
Qualys SSL Labs, August 10, 2026. The tested api.i-dialogue.com endpoint received an A rating for its TLS configuration. Results apply to the tested endpoint and date.
Sanitized OWASP ZAP passive scan summary dated February 11, 2025, showing zero high-risk alerts, five medium, three low, and three informational alerts.
OWASP ZAP passive scan, February 11, 2025. The reviewed passive scan reported 0 High, 5 Medium, 3 Low, and 3 Informational alerts across staging.i-dialogue.com, api.idialogue.app, and api.i-dialogue.com. Detailed findings and remediation context are available under NDA.

Security findings are evaluated in the context of the affected endpoint, exploitability, and business impact. Detailed vulnerability findings and remediation context are available under NDA when appropriate.

Security framework references

Pacific Apps uses the NIST Cybersecurity Framework (CSF) as an input to security policy and cybersecurity risk management.

The NIST AI Risk Management Framework (AI RMF) and MITRE ATLAS inform ongoing AI-risk and threat-modeling work.

These framework references do not represent certifications, attestations, or government approvals.

Documents and evidence access

Public assurance materials

Additional materials for enterprise review

  • detailed architecture and data-flow diagrams;
  • detailed vulnerability findings and remediation context;
  • security questionnaires and control evidence;
  • customer-specific provider and subprocessor reviews;
  • audit or penetration-test materials when available and appropriate to disclose; and
  • other sensitive assurance materials relevant to the proposed deployment.

Customer-specific security reviews

Enterprise deployments often require review of the exact Salesforce configuration and workflow rather than the platform in the abstract. iDialogue can provide a scoped review covering:

  1. Salesforce objects, fields, files, and integration identity;
  2. enabled agents, skills, tools, and Connections;
  3. processing providers and request-level storage settings;
  4. artifact, transcript, memory, log, and billing data classes;
  5. Room, member, sharing, and public-publishing access;
  6. retention and deletion requirements; and
  7. evidence needed for procurement or security review.

Vendor governance

Third-party providers are evaluated according to the data they process, the capabilities they provide, and their role in the iDialogue architecture. Reviews can include provider documentation, contractual safeguards, security controls, configuration, operational dependency, and offboarding requirements.

See the Third-Party Security Policy for additional information.

Need security documentation for your review?

We can provide architecture details, security questionnaires, customer-specific data-flow reviews, and additional assurance materials appropriate to your deployment. Sensitive materials may require an NDA. Contact support@idialogue.app.

Generated 2026-08-11T02:58:43.362553Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.