Citeply
PrivacyTermsTrust

Trust center

Trust is a product constraint

Citeply separates controls already proven in code from the infrastructure and independent validation still required before production.

Last updated 3 August 2026

Evidence before claims

No approved source means no affirmative answer.

Tenant before retrieval

Every resource lookup must stay inside the authorized customer boundary.

Preserve the workbook

Only confirmed response cells may be changed; structural risk is visible and guarded.

Current control status

Implemented

Workbook analysis runs locally in the current preview and preserves the original file.

Implemented

Unsupported answers are blocked when approved evidence is missing.

Implemented

Tenant-scoped database constraints and row-level security migrations are tested in code.

Implemented

The Graph client is restricted to an approved tenant and selected drive boundary.

Activation required

Production hosting, encrypted storage, backups, and operational monitoring.

Activation required

Microsoft Entra multi-tenant sign-in, consent, and token-vault integration.

Validation required

Twenty to thirty legally usable real questionnaires and preservation tests.

Validation required

Independent legal, privacy, threat-model, and penetration-test review.

Planned Microsoft permissions

Citeply will use delegated Microsoft Graph permissions, starting with basic sign-in and Files.Read for a file the signed-in user selects. Broader SharePoint access will not be requested unless a later feature requires it and the customer administrator explicitly authorizes it. Consent can be revoked in Microsoft Entra ID.

Data flow

  1. An authorized user selects a questionnaire and evidence sources.
  2. Citeply maps questions and retrieves only permitted evidence.
  3. Suggestions carry source locators, versions, owners, and expiry state.
  4. An authorized reviewer approves, edits, or routes each answer.
  5. Only safe, confirmed cells become eligible for export.

Report a security concern

The production security contact will be security@citeply.com. The mailbox must be activated and tested before public launch. Please do not send customer data or active credentials in an initial report.

© 2026 CiteplyEvidence-backed answers. Human-approved claims.