Third-Party Security Policy
Effective date: May 22, 2026
Last reviewed: May 22, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app
Purpose
Pacific Apps, Inc. uses infrastructure, AI, payment, communications, data, development, and other service providers to operate and extend iDialogue. This policy defines requirements for evaluating, contracting with, configuring, monitoring, and offboarding third-party providers based on the risk and access associated with each relationship.
Risk-based provider classification
Third-party providers are evaluated according to the risk, data, and capabilities involved in the relationship, including:
- the customer or personal data the provider receives;
- whether data is stored or processed transiently;
- access to credentials, production systems, or customer-facing actions;
- security, privacy, availability, financial, legal, and concentration risk;
- whether the provider is part of the core iDialogue service or an optional customer-enabled Connection; and
- whether the customer maintains its own provider account, contract, credentials, or administrative controls.
A Connection appearing in the iDialogue catalog does not mean it is configured for or used by a particular customer.
Due diligence
Provider due diligence is proportionate to the risk and role of the service. Reviews may consider:
- security and privacy documentation;
- Data Processing Addenda and contractual terms;
- architecture, hosting, and data location;
- retention and deletion practices;
- identity and access controls;
- encryption and key-management practices;
- incident-response obligations;
- business continuity and resilience;
- independent assessments or certifications where available; and
- material vulnerability or security history.
Assurance evidence is evaluated according to its scope, date, and applicability to the service being used. A provider's certification or security assessment does not automatically extend to iDialogue's configuration or a customer's workflow.
Contractual and configuration controls
Depending on the provider's role and risk, Pacific Apps applies appropriate contractual and technical safeguards, which may include:
- confidentiality, privacy, security, incident, deletion, and subprocessor terms;
- least-privileged credentials and customer- or tenant-scoped configuration;
- restrictions on provider training and optional data-sharing or service-improvement programs;
- endpoint- or request-level retention controls;
- audit, termination, export, and deletion rights; and
- documented contingency or exit plans for material dependencies.
Pacific Apps and OpenAI entered into a Data Processing Addendum on July 9, 2023. See the public summary and redacted executed agreement.
Customer-enabled Connections
iDialogue Connections allow customers to authorize optional external services for specific workflows. Depending on the service, a Connection may use customer-controlled OAuth authorization or credentials, or an iDialogue-managed service.
Customers control which optional Connections they authorize and should review:
- credential and authorization scope;
- enabled agent skills and tools;
- data sent to the service;
- permitted actions;
- usage and rate limits;
- cost and billing implications; and
- offboarding requirements.
The Connections catalog describes services that can be made available through iDialogue. It is not a universal list of subprocessors used for every customer.
Monitoring and change
Material providers are reassessed when changes to service scope, data use, contractual terms, ownership, hosting location, technical integration, security incidents, or assurance evidence materially affect the risk of the relationship.
Identified risks are assigned an owner and treated according to the Risk Assessment Policy.
Offboarding
Provider offboarding includes, as applicable:
- revoking credentials, tokens, and access;
- disabling or replacing dependent workflows;
- exporting or migrating required customer or operational data;
- requesting supported deletion from the provider;
- preserving records required for security, legal, financial, or contractual purposes; and
- confirming ownership and treatment of remaining dependencies.
Material provider transitions should include an identified owner and continuity or migration plan where service interruption could affect customers.
Provider and subprocessor information
Customers can request a current provider or subprocessor review applicable to their iDialogue deployment. Available information may include provider role, data processed, applicable Connections, contractual safeguards, and relevant security documentation.
Some architecture, security, or operational details may be provided through a security questionnaire, customer agreement, or under NDA.
Contact support@idialogue.app.