Privacy & Data Protection
How customer and personal data are processed, protected, and handled, including individual data requests.
Trust Center · Compliance & Policies
iDialogue publishes security and privacy policies, contractual safeguards, Salesforce review evidence, and point-in-time security testing so customers can evaluate the controls relevant to their deployment. Each artifact is presented with its applicable scope and date.
Pacific Apps, Inc., provider of iDialogue, maintains a security and privacy program that combines documented policies, contractual safeguards, provider governance, operational controls, Salesforce marketplace review, and security testing.
Independent certifications or attestations are identified explicitly when applicable. Framework references on this page describe security and risk-management inputs and should not be interpreted as certifications.
| Evidence | Scope | Date | Access |
|---|---|---|---|
| Salesforce AppExchange Security Review | Most recent Salesforce security review | April 9, 2025 | Public summary and scoped evidence |
| Force.com Source Scanner | Displayed managed-package source scan | February 18, 2025 | Sanitized public evidence |
| TLS assessment | 3rd party endpoint configuration analysis | August 10, 2026 | Public point-in-time evidence |
| OWASP ZAP passive scan | Displayed staging and API endpoints | February 11, 2025 | Sanitized summary; detailed context under NDA |
| OpenAI Data Processing Addendum | Contractual safeguards between Pacific Apps, Inc. and OpenAI | July 9, 2023 | Public summary and reviewed/redacted agreement |
| Architecture and data-flow review | Proposed or customer-specific deployment | Current when prepared | By request or under NDA |
| Security questionnaires and detailed findings | Applicable control and deployment scope | Current when prepared | By request or under NDA |
The Salesforce Security Review provides meaningful assurance for the managed package submitted to Salesforce. Hosted iDialogue services, customer-specific Salesforce configuration, external providers, and later releases have their own security considerations and controls.
How customer and personal data are processed, protected, and handled, including individual data requests.
How files, generated artifacts, transcripts, knowledge, logs, and financial records are retained and removed.
Transport, storage, credential, and key-management control objectives.
How security findings are identified, prioritized, remediated, verified, and disclosed.
How security risks are identified, assigned, treated, and reviewed over time.
How providers are evaluated through due diligence, contractual safeguards, ongoing review, and offboarding.
Pacific Apps, Inc. and OpenAI entered into a Data Processing Addendum on July 9, 2023. A reviewed and redacted copy is available publicly, with sensitive execution and account-identifying information removed.
The DPA provides contractual data-protection safeguards. Current endpoint behavior and provider data controls are documented separately because they can evolve independently of the agreement.
Security findings are evaluated in the context of the affected endpoint, exploitability, and business impact.
Pacific Apps uses the NIST Cybersecurity Framework (CSF) as an input to security policy and cybersecurity risk management.
The NIST AI Risk Management Framework (AI RMF) and MITRE ATLAS inform ongoing AI-risk and threat-modeling work.
Enterprise reviews can map available policies and evidence to access control, secure development and change management, vendor risk, vulnerability management, incident response, continuity, privacy and retention, and AI governance. Evidence is provided according to its actual scope, date, sensitivity, and relevance to the proposed deployment.
Enterprise deployments often require review of the exact Salesforce configuration and workflow rather than the platform in the abstract. iDialogue can provide a scoped review covering:
Third-party providers are evaluated according to the data they process, the capabilities they provide, and their role in the iDialogue architecture. Reviews can include provider documentation, contractual safeguards, security controls, configuration, operational dependency, and offboarding requirements.
See the Third-Party Security Policy for additional information.
We can provide architecture details, security questionnaires, customer-specific data-flow reviews, and additional assurance materials appropriate to your deployment. Sensitive materials may require an NDA. Contact support@idialogue.app.
Ask about this page, related knowledge or specific iDialogue product and support features.