Generate documents
Turn trusted Salesforce data and approved templates into proposals, agreements, handoff documents, and customer Experiences, with controls around data access, AI processing, human review, and delivery.
Security, governance, and assurance for iDialogue
iDialogue helps organizations securely use AI to generate documents, understand files, and automate Salesforce workflows. Explore how we protect customer data, govern AI agents, control access, and validate our security practices.
Turn trusted Salesforce data and approved templates into proposals, agreements, handoff documents, and customer Experiences, with controls around data access, AI processing, human review, and delivery.
Use AI to extract, summarize, classify, and act on information in Salesforce Files, with configurable controls for processing, agent actions, validation, and Salesforce writeback.
Understand what AI agents can do, where human review fits, and what happens before Salesforce data or customer-facing content changes.
Review how Salesforce identity, permissions, Connections, agent tools, file workflows, and sharing controls are configured.
Follow customer data through processing, storage, retention, external providers, access controls, and available assurance evidence.
Review security policies, data-processing practices, contractual safeguards, third-party providers, and available assurance materials.
Review the scope and evidence for iDialogue's successful AppExchange Security Review.
Understand Salesforce identity, OAuth, workflow context, permissions, and customer-configured access boundaries.
Review how iDialogue uses OpenAI, including API credentials, data processing, storage behavior, and customer configuration options.
Control which external services are connected and which approved agent skills are authorized to use them.
Control agent capabilities through run context, enabled tools, connection permissions, approval requirements, and audit records.
Understand how transient context, files, generated outputs, transcripts, memory, logs, and billing records are handled.
Understand how access is controlled for private customer Rooms, shared content, and deliberately public publishing.
Access security and privacy policies, Salesforce review evidence, scanning results, and other assurance materials.
Understand Salesforce and file data flows, encryption, retention, storage, Connections, sharing controls, and subprocessors.
Review how agent capabilities, tools, approvals, provider controls, transcripts, usage, and auditability are governed.
Access public policies, contractual safeguards, Salesforce Security Review information, vulnerability evidence, and other assurance materials.
Request security documentation at support@idialogue.app.
iDialogue sends only the context required by the configured feature or workflow. Depending on the workflow, this may include selected record fields, instructions, files, or prior conversation state. Processing may occur within iDialogue services and configured providers outside Salesforce. See the file and agent data flow.
Server-side Salesforce access is principally controlled by the configured Salesforce connection or integration identity. Enabled tools and workflow configuration provide additional boundaries. Because external workflows may use an integration identity rather than automatically reproducing the initiating user's row-level access and field-level security, customers should review the identity and permissions configured for each workflow. See Salesforce API Integration.
The iDialogue v2.19.0 managed package successfully completed Salesforce's AppExchange Security Review on April 9, 2025. The review provides independent assurance for the package and submission evaluated by Salesforce. Hosted services, later releases, customer configurations, and third-party providers may have separate security considerations. See review details.
OpenAI states that API data is not used to train its models unless the API customer opts in. Current reviewed iDialogue Responses API workflows use store=true where required to support threaded conversations and background work. OpenAI's current documentation states that stored Responses application state is retained for at least 30 days. Other data classes, including abuse-monitoring logs, uploaded files, conversations, and optional sharing programs, may have different controls and retention behavior. See provider data controls.
Yes. Customer-provided OpenAI API keys are supported for approved deployments and can be associated with the customer's organization in iDialogue. This gives the customer control over the provider account and provider-level administration. iDialogue workflow behavior, transcript handling, request-level storage settings, and provider retention should still be reviewed separately. See the OpenAI Connection.
An agent's authority is determined by its run context, enabled skills and tools, Salesforce or external-service Connections, supplied data, and workflow configuration. Delete operations are not offered through the current Salesforce data-manipulation tool. Human confirmation or review can be required before consequential actions, with the exact approval point determined by the workflow. See authority and approvals.
Connections make approved external services available to iDialogue workflows. A service appearing in the Connections catalog does not mean it is configured, authorized, or used within a particular customer organization. Administrators can review configured Connections and the skills enabled for each agent. See the Connections catalog.
Depending on the feature, iDialogue can read Salesforce Files, temporarily process file content, and store generated or shared artifacts in iDialogue-managed storage. Private customer Rooms and deliberately public publishing use different access models. Customers should review membership, invitation, domain, sharing, and publication settings for the specific Experience. See sharing and access.
Threaded agent workflows can retain user and assistant messages, model information, tool-call details, token usage, and credit records to support conversation continuity, administration, billing, and investigation. Operational and security logs are maintained separately. Retention and access controls should be evaluated by data class and applicable contract. See transcripts and audit.
iDialogue meters agent and processing activity using credits and records usage for billing and operations. Provider rate limits and model capacity are managed separately and may change over time. Higher-volume or governance-sensitive deployments may use customer-provided provider credentials and customer-managed provider limits. Background agents can continue processing after an interactive request, so customers should configure appropriate budgets, workflow permissions, and exception handling. See usage and cost controls.
Our team can provide a customer-specific security and data-flow review covering Salesforce access, selected fields and files, AI providers, agent capabilities, storage, sharing, and approval controls. Contact support@idialogue.app.
Ask about this page, related knowledge or specific iDialogue product and support features.