Secure account lifecycle
Local identity combines email verification, strong password hashing, tracked sessions and required MFA.
- TOTP and recovery codes
- Session revocation
- Sensitive-action step-up
Citeply uses layered identity, authorization, tenant context, file security, operational monitoring and deletion controls for sensitive questionnaire work.

Local identity combines email verification, strong password hashing, tracked sessions and required MFA.
Reading evidence, managing connectors, publishing answers and operating the platform are distinct powers.
Repository calls, object keys and background jobs carry tenant and workspace identity.
Verify actual content, quarantine new files and block processing until malware scanning passes.
Structured logs, correlation IDs, durable alerts and readiness probes support incident detection and response.
Request, billing settlement, grace period and verified erasure remain explicit and auditable.
Review privacy, security and operating commitments.
Open trust centerSee the current reporting and response process.
Review incident responseReview the current service provider register.
View subprocessorsApply for a guided 30-day pilot using synthetic or anonymized material. No payment or Microsoft 365 connection is required to begin.