Third-Party Security Policy

Third-Party Security Policy

Effective date: May 22, 2026
Last reviewed: May 22, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app

Purpose

Pacific Apps, Inc. uses infrastructure, AI, payment, communications, data, development, and other service providers to operate and extend iDialogue. This policy defines requirements for evaluating, contracting with, configuring, monitoring, and offboarding third-party providers based on the risk and access associated with each relationship.

Risk-based provider classification

Third-party providers are evaluated according to the risk, data, and capabilities involved in the relationship, including:

  • the customer or personal data the provider receives;
  • whether data is stored or processed transiently;
  • access to credentials, production systems, or customer-facing actions;
  • security, privacy, availability, financial, legal, and concentration risk;
  • whether the provider is part of the core iDialogue service or an optional customer-enabled Connection; and
  • whether the customer maintains its own provider account, contract, credentials, or administrative controls.

A Connection appearing in the iDialogue catalog does not mean it is configured for or used by a particular customer.

Due diligence

Provider due diligence is proportionate to the risk and role of the service. Reviews may consider:

  • security and privacy documentation;
  • Data Processing Addenda and contractual terms;
  • architecture, hosting, and data location;
  • retention and deletion practices;
  • identity and access controls;
  • encryption and key-management practices;
  • incident-response obligations;
  • business continuity and resilience;
  • independent assessments or certifications where available; and
  • material vulnerability or security history.

Assurance evidence is evaluated according to its scope, date, and applicability to the service being used. A provider's certification or security assessment does not automatically extend to iDialogue's configuration or a customer's workflow.

Contractual and configuration controls

Depending on the provider's role and risk, Pacific Apps applies appropriate contractual and technical safeguards, which may include:

  • confidentiality, privacy, security, incident, deletion, and subprocessor terms;
  • least-privileged credentials and customer- or tenant-scoped configuration;
  • restrictions on provider training and optional data-sharing or service-improvement programs;
  • endpoint- or request-level retention controls;
  • audit, termination, export, and deletion rights; and
  • documented contingency or exit plans for material dependencies.

Pacific Apps and OpenAI entered into a Data Processing Addendum on July 9, 2023. See the public summary and redacted executed agreement.

Customer-enabled Connections

iDialogue Connections allow customers to authorize optional external services for specific workflows. Depending on the service, a Connection may use customer-controlled OAuth authorization or credentials, or an iDialogue-managed service.

Customers control which optional Connections they authorize and should review:

  • credential and authorization scope;
  • enabled agent skills and tools;
  • data sent to the service;
  • permitted actions;
  • usage and rate limits;
  • cost and billing implications; and
  • offboarding requirements.

The Connections catalog describes services that can be made available through iDialogue. It is not a universal list of subprocessors used for every customer.

Monitoring and change

Material providers are reassessed when changes to service scope, data use, contractual terms, ownership, hosting location, technical integration, security incidents, or assurance evidence materially affect the risk of the relationship.

Identified risks are assigned an owner and treated according to the Risk Assessment Policy.

Offboarding

Provider offboarding includes, as applicable:

  • revoking credentials, tokens, and access;
  • disabling or replacing dependent workflows;
  • exporting or migrating required customer or operational data;
  • requesting supported deletion from the provider;
  • preserving records required for security, legal, financial, or contractual purposes; and
  • confirming ownership and treatment of remaining dependencies.

Material provider transitions should include an identified owner and continuity or migration plan where service interruption could affect customers.

Provider and subprocessor information

Customers can request a current provider or subprocessor review applicable to their iDialogue deployment. Available information may include provider role, data processed, applicable Connections, contractual safeguards, and relevant security documentation.

Some architecture, security, or operational details may be provided through a security questionnaire, customer agreement, or under NDA.

Contact support@idialogue.app.

Related information

Generated 2026-08-11T02:58:43.353775Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.