Security, Privacy & Data Protection
Encryption, security standards, SSO, MFA, residency, and retention.
How is my data secured?
Respectly runs on Microsoft Azure, and we apply the standard set of enterprise security controls:
- Encryption in transit — TLS 1.2 or higher on every external connection.
- Encryption at rest — AES-256 for databases, file storage, and backups.
- Network isolation — services run in private Azure networks with no public database endpoints.
- Identity & access — all sign-in goes through Microsoft Entra External ID with federated provider support.
- Audit logging — every tenant-affecting action is recorded with actor, timestamp, and IP.
How does Respectly handle security standards?
Respectly is built on Microsoft Azure infrastructure and follows layered security controls with regular internal and third-party security reviews. Contact security@respectly.ai for our latest security documentation and architecture guidance.
Do you support Single Sign-On (SSO)?
Federated sign-in with Google, Microsoft, and Apple is available on all plans. Enterprise SSO with SAML or OIDC against your own identity provider (Okta, Azure AD, Google Workspace, OneLogin, etc.) is available on Enterprise; contact sales to enable it.
Do you support multi-factor authentication?
Yes. Users can enable TOTP-based MFA from Settings → Security, and admins can require MFA for their tenant. Federated sign-ins use the MFA configuration of the identity provider (Google, Microsoft, Apple).
Where is my data stored?
Primary data is stored in Microsoft Azure data centers. The default region for new tenants is East US 2. Enterprise customers can request specific regions (Western Europe, UK South, Australia East, Canada Central, etc.) at contract time. Data does not leave its assigned region except for replicated backups within Azure's geo-redundant storage.
How long is my data kept?
While your account is active, all contacts, messages, forms, documents, and audit logs are retained indefinitely. If you delete a contact, the contact and all associated personal data are permanently removed after a 24-hour grace period. If you cancel your account, your data is retained for 30 days to allow reactivation, then permanently deleted. Audit logs required by regulation (consent evidence, signed documents) may be retained longer where law requires.
Can I delete my account?
Yes. From Settings → Account → Delete Account you can request permanent deletion. The 24-hour grace period applies — during that window the request can be canceled. After the grace period, all contacts, messages, custom branding, payment information, and audit data are permanently removed, with the exception of records we are legally required to retain.
Can I use Respectly for sensitive healthcare workflows?
Respectly supports encrypted messaging, consent capture, and audit trails for healthcare operations. If your workflow includes highly regulated medical records, review your legal requirements and contact sales for architecture guidance before rollout.