Security is built into ReFresh across hosting, encryption, access control, authentication, and monitoring.
Your data is encrypted in transit and at rest, and isolated per organisation.
ReFresh holds recognised, independently-audited security certifications, with more on the roadmap.
For the full detail, including certifications, sub-processors, and current audit evidence, see the ReFresh Trust Centre.
How ReFresh protects your data
ReFresh handles psychosocial safety data, which is sensitive by definition, so security is designed in rather than added on:
Encryption. Your data is encrypted in transit and at rest.
Isolation. Each organisation's data is logically isolated, so one customer's data is never visible to another.
Access control. Access is governed by granular, per-feature permissions, enforced consistently across the app, the service layer, and the database. Multi-factor authentication is available to all users.
Monitoring and auditing. System activity is logged and retained, and ReFresh undergoes independent third-party security audits.
Certifications and evidence
ReFresh maintains recognised security certifications and is expanding its coverage over time. For the current certification status, audit reports (available under NDA), the sub-processor list, and data-residency detail, see the ReFresh Trust Centre (trust.refresh.tech). Your ReFresh account contact can help with security reviews and procurement questions.
Reporting a security concern
If you suspect a vulnerability or security issue, see "Reporting a security concern".
