Security & Data Handling

Trust Center · Security & Data Handling

Understand where your data goes and how it is protected

iDialogue connects Salesforce data, files, AI processing, and customer-facing workflows. This page explains how data is accessed, processed, stored, shared, and retained across those workflows.

Shared responsibility

Control area iDialogue controls Customer controls
Application Secure development, platform access controls, tenant-aware processing, monitoring, and documented feature behavior Choose enabled features and users; review intended use and outputs
Salesforce Support OAuth/API integration and scoped workflow configuration Configure the integration identity, permissions, connected-app policies, records, fields, and sharing model
AI and processing providers Contract with providers, configure iDialogue-managed accounts, and document request behavior Approve providers and data classes; configure customer-provided accounts or keys where selected
Files and outputs Process and store data required by the selected workflow Classify source files, choose output destinations, review generated content, and manage retention requirements
Sharing Provide invitation, member, Room, and public-publishing capabilities Decide who receives access and verify whether a destination is private, authenticated, or public
Salesforce remains the business system of record. Selected Salesforce data may be processed outside Salesforce when required by configured workflows, using iDialogue services and approved processing providers.

Salesforce API Integration

iDialogue accesses Salesforce through a configured Salesforce Connection. For server-side workflows, that Connection or integration identity defines the primary Salesforce permission boundary.

Customers should apply least privilege and review:

  • OAuth and connected-app policy;
  • the integration user's object, field, record, and file access;
  • the agents, skills, and tools enabled for each run context;
  • the record fields and files selected as input;
  • any approval checkpoint before a write or external share; and
  • scheduled or background workflows that can run without an active browser session.

Some workflows also include initiating-user or Salesforce page context. External processing should not be assumed to automatically reproduce all row-level sharing and field-level security of the initiating Salesforce user. Customers should verify the Salesforce identity used by each workflow.

The current Salesforce data-manipulation tool supports insert, update, and upsert operations. Delete is not supported.

File and agent data flow

A typical governed workflow follows the sequence below. Exact processing steps vary by feature and configuration.

sequenceDiagram
    actor User as Salesforce user or automation
    participant SF as Salesforce permissions and Files
    participant ID as iDialogue control plane
    participant Agent as Configured agent and tools
    participant Processor as Approved processor
    participant Audit as Transcript and usage controls

    User->>SF: Start an approved workflow
    SF->>ID: Send authenticated context and file references
    ID->>ID: Apply tenant scope and execution policy
    ID->>Agent: Provide permitted context and tools
    Agent->>Processor: Send task-specific content when required
    Processor-->>Agent: Return task result
    Agent->>Audit: Record configured audit and usage data
    Agent-->>SF: Propose or perform the permitted outcome
    SF-->>User: Review result and continue the business process

Processor calls, artifact storage, transcript detail, and Salesforce writeback depend on the selected feature, Connection identity, and workflow configuration.

See how agent authority and approvals fit this flow.

Data lifecycle by class

Different categories of data have different processing and retention requirements:

Data class Why it may be processed Handling and retention
Transient Salesforce context Merge fields, answer a question, or determine a permitted action May also appear in provider request state, transcripts, or operational logs depending on the workflow
Source files OCR, extraction, summarization, document Q&A, or generation input May be downloaded for processing, sent to an approved provider, indexed, or associated with stored workflow state
Generated artifacts Documents, images, Room content, and other outputs Stored when the selected feature must return, share, publish, or later retrieve the artifact
Agent transcripts and tool details Resume threaded conversations, investigate behavior, and meter work Can include user and assistant messages, model information, tool-call details, token usage, and credits
Memory and indexed knowledge Retrieval across permitted sessions or files Persists according to the applicable memory, knowledge, account, or contract lifecycle
Operational and security logs Reliability, fraud prevention, support, and incident investigation Managed separately from agent transcripts and retained according to operational, legal, and provider requirements
Billing and credit records Meter service consumption and reconcile charges Retained for financial, contractual, tax, dispute, and audit requirements

Read the public Data Retention Policy and Privacy Policy. Contract terms can add customer-specific commitments.

Tenant isolation

iDialogue associates customer configuration, workflow state, transcripts, and usage records with the applicable Salesforce organization or tenant. Tenant identifiers and authorization controls are used throughout the platform to scope access to customer data.

For higher-assurance evaluations, detailed architecture, endpoint information, and customer-specific data-flow reviews are available under NDA.

Encryption and transport

iDialogue requires encrypted transport for supported production web and API paths. The platform also uses cloud storage and managed services with encryption capabilities. Exact protocols, keys, storage services, and responsibilities vary by component and customer configuration.

Point-in-time TLS evidence for the multi-tenant API is available in Compliance & Policies. This evidence demonstrates the tested endpoint configuration at the time of review. See the Encryption Policy for documented control objectives.

Connections

iDialogue Connections allow approved workflows to access Salesforce, AI providers, communications platforms, data services, and other external systems. Administrators control which Connections are configured, and agents can use only the Connections exposed through their enabled skills.

Three Connection states are intentionally distinct:

  1. Available: a Connection appears in the product catalog.
  2. Configured: an administrator has enabled credentials or completed authorization.
  3. Used: a particular agent or workflow has an enabled skill that invokes the Connection.

Available does not mean configured, and configured does not mean used.

A Connection appearing in the catalog does not mean customer data is sent to that service. Review the Connections catalog, the customer organization's configured Connections, and the skills enabled for the applicable agent.

Sharing, Rooms, and public publishing

iDialogue supports several distinct delivery and access models:

  • Salesforce output returns or attaches a result to the configured Salesforce workflow.
  • Invitation-based Rooms or Experiences use member, invitation, token, and session controls for customer-facing access.
  • Public publishing deliberately creates content intended for anonymous web access.

These access models are intentionally distinct. Private Rooms and Experiences use configured membership and access controls, while public publishing is explicitly intended for anonymous web access.

Administrators should review membership, links, domains, expiration, and publication settings before distributing sensitive content, and revoke or archive access when the business purpose ends.

Retention and deletion

Retention is managed by data class rather than through a single universal retention period. Salesforce context, provider request state, transcripts, generated artifacts, knowledge, operational logs, and financial records can have different lifecycle requirements.

Current reviewed iDialogue Responses API workflows use store=true where stored provider state is required. OpenAI provider state is separate from iDialogue application retention and customer contract terms. See AI & Agent Governance for current OpenAI storage and retention details.

Deletion requests may involve Salesforce records, iDialogue application state, stored artifacts or knowledge, and applicable processing-provider state. Certain records may be retained where required for security investigations, legal obligations, backups, financial records, dispute resolution, or contractual requirements.

See the Data Retention Policy for additional information.

Providers and subprocessors

Pacific Apps, Inc. uses infrastructure and processing providers to operate iDialogue. Provider involvement depends on the feature and workflow being used.

AWS services support core platform hosting and storage. OpenAI is used for configured AI-assisted workflows. Optional Connections involve additional external services only when they are configured and invoked by an approved workflow.

The Third-Party Security Policy describes provider review expectations. The OpenAI Data Processing Addendum summary provides information about the applicable public contractual artifact.

For a current customer-specific provider inventory and data-flow review, contact support@idialogue.app.

Planning a security or data-flow review?

We can map a proposed workflow from Salesforce through processing, storage, agent actions, and final delivery, including the specific objects, files, providers, permissions, and retention requirements involved. Contact support@idialogue.app.

Generated 2026-08-11T02:58:43.367213Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.