Privacy & Data Protection
How customer and personal data are processed, protected, and handled, including individual data requests.
Trust Center · Compliance & Policies
iDialogue publishes security and privacy policies, contractual safeguards, Salesforce review evidence, and point-in-time security testing so customers can evaluate the controls relevant to their deployment. Each artifact is presented with its applicable scope and date.
Pacific Apps, Inc., provider of iDialogue, maintains a security and privacy program that combines documented policies, contractual safeguards, provider governance, operational controls, Salesforce marketplace review, and security testing.
Independent certifications or attestations are identified explicitly when applicable. Framework references on this page describe security and risk-management inputs and should not be interpreted as certifications.
The Salesforce Security Review provides meaningful assurance for the managed package submitted to Salesforce. Hosted iDialogue services, customer-specific Salesforce configuration, external providers, and later releases have their own security considerations and controls.
How customer and personal data are processed, protected, and handled, including individual data requests.
How files, generated artifacts, transcripts, knowledge, logs, and financial records are retained and removed.
Transport, storage, credential, and key-management control objectives.
How security findings are identified, prioritized, remediated, verified, and disclosed.
How security risks are identified, assigned, treated, and reviewed over time.
How providers are evaluated through due diligence, contractual safeguards, ongoing review, and offboarding.
Pacific Apps, Inc. and OpenAI entered into a Data Processing Addendum on July 9, 2023. A reviewed and redacted copy is available publicly, with sensitive execution and account-identifying information removed.
The DPA provides contractual data-protection safeguards. Current endpoint behavior and provider data controls are documented separately because they can evolve independently of the agreement.
Security findings are evaluated in the context of the affected endpoint, exploitability, and business impact. Detailed vulnerability findings and remediation context are available under NDA when appropriate.
Pacific Apps uses the NIST Cybersecurity Framework (CSF) as an input to security policy and cybersecurity risk management.
The NIST AI Risk Management Framework (AI RMF) and MITRE ATLAS inform ongoing AI-risk and threat-modeling work.
These framework references do not represent certifications, attestations, or government approvals.
Enterprise deployments often require review of the exact Salesforce configuration and workflow rather than the platform in the abstract. iDialogue can provide a scoped review covering:
Third-party providers are evaluated according to the data they process, the capabilities they provide, and their role in the iDialogue architecture. Reviews can include provider documentation, contractual safeguards, security controls, configuration, operational dependency, and offboarding requirements.
See the Third-Party Security Policy for additional information.
We can provide architecture details, security questionnaires, customer-specific data-flow reviews, and additional assurance materials appropriate to your deployment. Sensitive materials may require an NDA. Contact support@idialogue.app.
Ask about this page, related knowledge or specific iDialogue product and support features.