Trust Center

Security, governance, and assurance for iDialogue

Trust starts with clear answers

iDialogue connects Salesforce records, files, people, and AI-assisted workflows. This Trust Center explains how access is scoped, how agent actions are governed, how customer information is handled, and what evidence is available for security and procurement review.

Explore trust and security or browse a functional area.

Clear answers to common questions

Can another customer or a public ChatGPT user access our Salesforce data?

No. Connecting iDialogue to Salesforce does not make CRM data available to public ChatGPT users or other iDialogue customers. Workflows operate within the customer's configured Salesforce connection and iDialogue tenant context. The connection identity, selected data, enabled tools, workflow rules, approvals, and sharing settings determine access.

Is our information used to train OpenAI models?

Customer data processed through the iDialogue-managed OpenAI API integration is not used to train OpenAI models. Model training is separate from the provider processing and application state used to deliver API functionality.

What can an iDialogue agent access or change?

An agent receives only the context and capabilities made available to its configured workflow. The Salesforce API connection user establishes the primary Salesforce permission boundary. Enabled skills, tools, object and field access, workflow instructions, and approval requirements narrow that authority further.

Why does iDialogue retain some information?

Retention supports defined business purposes. Approved dialogue context can support continuity. Task inputs support a requested operation. Repository artifacts and Experience content support review, delivery, eSignature, and later retrieval. Operational records support reliability, security, support, usage reconciliation, and billing. These data classes have different lifecycles.

How do iDialogue Experiences and Document Rooms handle customer information?

iDialogue Experiences and Document Rooms are secure customer-facing workspaces for documents, checklists, forms, uploads, review, and eSignature. Data collected through a configured Experience may update the corresponding Salesforce record. Documents and related activity can remain available in the Room for the configured business lifecycle.

What evidence is available for enterprise review?

Public materials include security and privacy policies, Salesforce AppExchange Security Review information, provider contractual documentation, and scoped testing evidence. Detailed architecture, data-flow reviews, vulnerability findings, questionnaires, and other sensitive materials may be provided under NDA.

Start with your role

Salesforce Admin

Find configuration guidance for Salesforce identity, permissions, Connections, agent tools, and sharing controls.

Review Salesforce API integration

IT, security, or CISO

Review data lifecycles, tenant isolation, external providers, and available assurance evidence.

Review the data lifecycle

Procurement, Legal, or Compliance

Find public policies, contractual safeguards, and available assurance materials.

Review policies and evidence

Explore trust and security

Salesforce API Integration

Understand how the Salesforce API connection user configured by the Salesforce Admin sets the primary permission boundary.

OpenAI Integration

Review provider governance, dialogue continuity, task processing, application state, and customer configuration options.

Connections

Control which external services are connected and which approved agent skills are authorized to use them.

Agent Authority & Approval

Control agent capabilities through the Salesforce connection user, enabled capabilities, workflow rules, approvals, and monitoring.

Data Lifecycle

Understand how dialogue history, task inputs, Experience and Room content, repository artifacts, Salesforce writeback, and operational records are handled.

Sharing, Rooms & Publishing

Understand how invited members access private Experiences and Document Rooms, how content is shared for review or eSignature, and how deliberately public publishing differs.

Policies & Evidence

Access security and privacy policies, Salesforce review evidence, scanning results, and other assurance materials.

Security model

Layered iDialogue security model connecting a Salesforce user and configured Salesforce org to iDialogue workflow controls, selected processing providers, stored artifacts, and audit records.
iDialogue uses layered controls across Salesforce, workflow configuration, AI providers, storage, sharing, and human review. Administrators control the connections, data context, agent capabilities, and approval requirements available to each workflow.

Connecting a Salesforce org does not create a public or cross-customer query path. Each workflow resolves within the applicable organization, connection, and configured access model.

Security follows the workflow. Different iDialogue features may process selected Salesforce data, files, conversation state, or generated artifacts. Our Trust Center documents those data flows so customers can evaluate each deployment based on how it is actually configured and used.

Three trust pillars

Security & Data Handling

Understand Salesforce and file data flows, encryption, retention, storage, Connections, sharing controls, and subprocessors.

AI & Agent Governance

Review how agent capabilities, tools, approvals, provider controls, transcripts, usage, and auditability are governed.

Compliance & Policies

Access public policies, contractual safeguards, Salesforce Security Review information, vulnerability evidence, and other assurance materials.

Documents and evidence

Available by request or under NDA

  • Detailed architecture and endpoint diagrams
  • Detailed vulnerability scan findings and remediation context
  • Security questionnaires and customer-specific data-flow reviews
  • Additional assurance materials containing sensitive operational details

Request security documentation at support@idialogue.app.

Additional technical questions

What did the April 9, 2025 Salesforce Security Review cover?

The iDialogue managed package successfully completed Salesforce's AppExchange Security Review on April 9, 2025. The review provides independent assurance for the package version and submission evaluated by Salesforce. Hosted services, later releases, customer configurations, and third-party providers have separate scopes. See review details.

Can a customer use its own OpenAI API key?

Yes. Customer-provided OpenAI API keys are supported for approved deployments and can be associated with the customer's organization in iDialogue. The customer controls provider-account administration, including usage, billing, rate limits, and available settings. The key does not expand Salesforce access or replace iDialogue workflow controls. See the OpenAI Connection.

Which Connections can an agent use?

An agent can use only the Connections made available through its enabled skills. A service appearing in the Connections catalog does not mean it is configured, authorized, or used within a particular customer organization. Administrators can review configured Connections and the skills enabled for each agent. See the Connections catalog.

Is iDialogue a Salesforce native application?

Yes. The iDialogue managed package provides 100% of the administrative experience within Salesforce. Some Connections, such as Twilio, Stripe, and Apollo.io, may require visiting a third-party service to configure or manage the integration.

How are credits, rate limits, overages, and background agents controlled?

iDialogue meters agent and processing activity using credits and records usage for billing and operations. Provider rate limits and model capacity are managed separately and may change over time. Administrators can define budgets and workflow permissions, monitor background work, and stop it when needed. See usage and execution controls.

Are any desktop or MCP connections required to use iDialogue?

No. iDialogue is a cloud-hosted solution. Content management and agentic processes run in cloud services, including Salesforce and our AWS subprocessor. Desktop AI and MCP connections are not required or currently supported.

Planning an enterprise deployment?

Our team can provide a customer-specific security and data-flow review covering Salesforce access, selected fields and files, AI providers, agent capabilities, storage, sharing, and approval controls. Contact support@idialogue.app.

iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.