Vulnerability Management Policy

Vulnerability Management Policy

Effective date: May 22, 2026
Last reviewed: May 22, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app

Purpose

Pacific Apps, Inc. maintains a risk-based vulnerability management program to identify, assess, prioritize, remediate, and verify vulnerabilities affecting iDialogue applications, Salesforce package code, dependencies, infrastructure, and externally reachable services.

Identification sources

Vulnerabilities are identified through applicable sources including:

  • secure development practices and code review;
  • Salesforce submission and source-scanning processes;
  • dependency, static, dynamic, passive, and configuration scanning;
  • cloud, platform, and provider security advisories;
  • operational monitoring and incident investigation;
  • reports from customers, researchers, employees, and partners; and
  • point-in-time transport and endpoint-security testing.

No single scanner or testing method is treated as complete coverage.

Triage and prioritization

Findings are evaluated in context rather than prioritized solely by a scanner-assigned severity.

Triage considers:

  • the affected component and deployment;
  • exploitability and external exposure;
  • privileges and required user interaction;
  • confidentiality, integrity, availability, financial, and privacy impact;
  • customer data and tenant-isolation implications;
  • active exploitation and available compensating controls;
  • vendor or dependency guidance; and
  • operational risk associated with remediation.

Remediation

Validated findings are assigned an accountable owner and risk-based treatment.

Treatment may include:

  • code or configuration changes;
  • dependency updates;
  • access restrictions;
  • monitoring;
  • compensating controls;
  • provider remediation;
  • documented risk acceptance; or
  • service retirement.

Remediation timing is based on severity, exploitability, exposure, customer impact, available mitigations, and operational risk. Applicable contractual commitments are incorporated into remediation requirements.

Verification and closure

A finding is closed only after appropriate verification or documented risk acceptance.

Verification may include focused testing, rescanning, code review, deployment validation, configuration review, or provider confirmation.

Repeated or systemic findings may result in changes to development practices, testing, architecture, monitoring, or provider governance.

Reporting vulnerabilities

Suspected vulnerabilities should be reported privately to support@idialogue.app with the affected service or endpoint, reproduction steps, observed behavior, and other information useful for investigation.

Researchers must not access data that does not belong to them, intentionally disrupt service, or publicly disclose exploitable details before Pacific Apps has had a reasonable opportunity to investigate and coordinate remediation.

Customer notification is provided as required by applicable law and contract when a confirmed security issue materially affects customer data or service.

Security testing and assurance evidence

The Compliance & Policies page publishes scoped evidence from Salesforce source scanning, OWASP ZAP passive scanning, and Qualys TLS testing.

These artifacts provide point-in-time evidence for the tested code or endpoints. Point-in-time scanner results do not represent complete vulnerability coverage.

Detailed vulnerability findings, remediation information, and additional security evidence may be provided under NDA where appropriate.

Related information

Generated 2026-08-11T02:58:43.355498Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.