Trust center
Trust is a product constraint
Citeply separates controls already proven in code from the infrastructure and independent validation still required before production.
Last updated 3 August 2026Evidence before claims
No approved source means no affirmative answer.
Tenant before retrieval
Every resource lookup must stay inside the authorized customer boundary.
Preserve the workbook
Only confirmed response cells may be changed; structural risk is visible and guarded.
Current control status
Workbook analysis runs locally in the current preview and preserves the original file.
Unsupported answers are blocked when approved evidence is missing.
Tenant-scoped database constraints and row-level security migrations are tested in code.
The Graph client is restricted to an approved tenant and selected drive boundary.
Production hosting, encrypted storage, backups, and operational monitoring.
Microsoft Entra multi-tenant sign-in, consent, and token-vault integration.
Twenty to thirty legally usable real questionnaires and preservation tests.
Independent legal, privacy, threat-model, and penetration-test review.
Planned Microsoft permissions
Citeply will use delegated Microsoft Graph permissions, starting with basic sign-in and Files.Read for a file the signed-in user selects. Broader SharePoint access will not be requested unless a later feature requires it and the customer administrator explicitly authorizes it. Consent can be revoked in Microsoft Entra ID.
Data flow
- An authorized user selects a questionnaire and evidence sources.
- Citeply maps questions and retrieves only permitted evidence.
- Suggestions carry source locators, versions, owners, and expiry state.
- An authorized reviewer approves, edits, or routes each answer.
- Only safe, confirmed cells become eligible for export.
Report a security concern
The production security contact will be security@citeply.com. The mailbox must be activated and tested before public launch. Please do not send customer data or active credentials in an initial report.