Trust Center

Security, governance, and assurance for iDialogue

Enterprise trust for AI-powered Salesforce workflows

iDialogue helps organizations securely use AI to generate documents, understand files, and automate Salesforce workflows. Explore how we protect customer data, govern AI agents, control access, and validate our security practices.

Explore trust and security or browse a functional area.

Generate documents

Turn trusted Salesforce data and approved templates into proposals, agreements, handoff documents, and customer Experiences, with controls around data access, AI processing, human review, and delivery.

Review the document data flow

Understand files

Use AI to extract, summarize, classify, and act on information in Salesforce Files, with configurable controls for processing, agent actions, validation, and Salesforce writeback.

Review governed file workflows

Start with your role

Business or Salesforce user

Understand what AI agents can do, where human review fits, and what happens before Salesforce data or customer-facing content changes.

Review authority and approvals

Salesforce Admin

Review how Salesforce identity, permissions, Connections, agent tools, file workflows, and sharing controls are configured.

Review Salesforce API integration

IT, security, or CISO

Follow customer data through processing, storage, retention, external providers, access controls, and available assurance evidence.

Review the data lifecycle

Procurement, Legal, or Compliance

Review security policies, data-processing practices, contractual safeguards, third-party providers, and available assurance materials.

Review policies and evidence

Explore trust and security

Salesforce API Integration

Understand Salesforce identity, OAuth, workflow context, permissions, and customer-configured access boundaries.

OpenAI Integration

Review how iDialogue uses OpenAI, including API credentials, data processing, storage behavior, and customer configuration options.

Connections

Control which external services are connected and which approved agent skills are authorized to use them.

Agent Authority & Approval

Control agent capabilities through run context, enabled tools, connection permissions, approval requirements, and audit records.

Data Lifecycle

Understand how transient context, files, generated outputs, transcripts, memory, logs, and billing records are handled.

Sharing, Rooms & Publishing

Understand how access is controlled for private customer Rooms, shared content, and deliberately public publishing.

Policies & Evidence

Access security and privacy policies, Salesforce review evidence, scanning results, and other assurance materials.

Security model

Layered iDialogue security model connecting a Salesforce user and configured Salesforce org to iDialogue workflow controls, selected processing providers, stored artifacts, and audit records.
iDialogue uses layered controls across Salesforce, workflow configuration, AI providers, storage, sharing, and human review. Administrators control the connections, data context, agent capabilities, and approval requirements available to each workflow.
Security follows the workflow. Different iDialogue features may process selected Salesforce data, files, conversation state, or generated artifacts. Our Trust Center documents those data flows so customers can evaluate each deployment based on how it is actually configured and used.

Three trust pillars

Security & Data Handling

Understand Salesforce and file data flows, encryption, retention, storage, Connections, sharing controls, and subprocessors.

AI & Agent Governance

Review how agent capabilities, tools, approvals, provider controls, transcripts, usage, and auditability are governed.

Compliance & Policies

Access public policies, contractual safeguards, Salesforce Security Review information, vulnerability evidence, and other assurance materials.

Documents and evidence

Available by request or under NDA

  • Detailed architecture and endpoint diagrams
  • Detailed vulnerability scan findings and remediation context
  • Security questionnaires and customer-specific data-flow reviews
  • Additional assurance materials containing sensitive operational details

Request security documentation at support@idialogue.app.

Frequently asked questions

What Salesforce data leaves Salesforce when a document or file workflow runs?

iDialogue sends only the context required by the configured feature or workflow. Depending on the workflow, this may include selected record fields, instructions, files, or prior conversation state. Processing may occur within iDialogue services and configured providers outside Salesforce. See the file and agent data flow.

Which Salesforce identity and permissions apply?

Server-side Salesforce access is principally controlled by the configured Salesforce connection or integration identity. Enabled tools and workflow configuration provide additional boundaries. Because external workflows may use an integration identity rather than automatically reproducing the initiating user's row-level access and field-level security, customers should review the identity and permissions configured for each workflow. See Salesforce API Integration.

What did the April 9, 2025 Salesforce Security Review cover?

The iDialogue v2.19.0 managed package successfully completed Salesforce's AppExchange Security Review on April 9, 2025. The review provides independent assurance for the package and submission evaluated by Salesforce. Hosted services, later releases, customer configurations, and third-party providers may have separate security considerations. See review details.

Does OpenAI train on API data, and how is stored state retained?

OpenAI states that API data is not used to train its models unless the API customer opts in. Current reviewed iDialogue Responses API workflows use store=true where required to support threaded conversations and background work. OpenAI's current documentation states that stored Responses application state is retained for at least 30 days. Other data classes, including abuse-monitoring logs, uploaded files, conversations, and optional sharing programs, may have different controls and retention behavior. See provider data controls.

Can a customer use its own OpenAI API key?

Yes. Customer-provided OpenAI API keys are supported for approved deployments and can be associated with the customer's organization in iDialogue. This gives the customer control over the provider account and provider-level administration. iDialogue workflow behavior, transcript handling, request-level storage settings, and provider retention should still be reviewed separately. See the OpenAI Connection.

What can an agent read or change, and when is approval required?

An agent's authority is determined by its run context, enabled skills and tools, Salesforce or external-service Connections, supplied data, and workflow configuration. Delete operations are not offered through the current Salesforce data-manipulation tool. Human confirmation or review can be required before consequential actions, with the exact approval point determined by the workflow. See authority and approvals.

Which Connections can an agent use?

Connections make approved external services available to iDialogue workflows. A service appearing in the Connections catalog does not mean it is configured, authorized, or used within a particular customer organization. Administrators can review configured Connections and the skills enabled for each agent. See the Connections catalog.

Where are uploaded and generated files stored, and who can access Rooms or public content?

Depending on the feature, iDialogue can read Salesforce Files, temporarily process file content, and store generated or shared artifacts in iDialogue-managed storage. Private customer Rooms and deliberately public publishing use different access models. Customers should review membership, invitation, domain, sharing, and publication settings for the specific Experience. See sharing and access.

What transcript, tool, usage, and audit information is retained?

Threaded agent workflows can retain user and assistant messages, model information, tool-call details, token usage, and credit records to support conversation continuity, administration, billing, and investigation. Operational and security logs are maintained separately. Retention and access controls should be evaluated by data class and applicable contract. See transcripts and audit.

How are credits, rate limits, overages, and background agents controlled?

iDialogue meters agent and processing activity using credits and records usage for billing and operations. Provider rate limits and model capacity are managed separately and may change over time. Higher-volume or governance-sensitive deployments may use customer-provided provider credentials and customer-managed provider limits. Background agents can continue processing after an interactive request, so customers should configure appropriate budgets, workflow permissions, and exception handling. See usage and cost controls.

Planning an enterprise deployment?

Our team can provide a customer-specific security and data-flow review covering Salesforce access, selected fields and files, AI providers, agent capabilities, storage, sharing, and approval controls. Contact support@idialogue.app.

iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.