Security and Privacy
How ReFresh keeps your data safe, how single sign-on and multi-factor authentication work, where your data lives, and how we handle privacy and your data rights.
By Taylor1 author12 articles
Single Sign-On (SSO)
Set up single sign-on so your team signs in with your identity provider with domain verification and role mapping.
- Setting up and managing SSOHow to set up and manage Single Sign-On in ReFresh: verifying domains, adding and switching identity-provider connections, assigning roles, testing, and activating.
- Microsoft Entra IDConnect Microsoft Entra ID (formerly Azure AD) so your Microsoft 365 users sign in to ReFresh with their work accounts. ReFresh connects to Entra over OpenID Connect (OIDC).
- Google WorkspaceConnect Google Workspace so your team signs in to ReFresh with their Google accounts. ReFresh connects to Google over SAML 2.0.
- OktaConnect Okta so your workforce signs in to ReFresh with their Okta accounts. Okta supports both OpenID Connect (OIDC) and SAML; use OIDC unless you have a specific reason not…
- JumpCloudConnect JumpCloud so your directory users sign in to ReFresh with their JumpCloud accounts. JumpCloud supports both OpenID Connect (OIDC) and SAML; use OIDC unless you have a reason not…
- Other provider (SAML or OIDC)ReFresh works with any identity provider that supports OpenID Connect (OIDC) or SAML 2.0, including Ping Identity, OneLogin, Auth0, Keycloak, and AD FS. In the wizard, choose Other Provider, then…
- Troubleshooting SSO and loginFixes for the most common SSO and login problems in ReFresh, covering domain verification, connection setup, sign-in denials, and the exact error messages you might see.
Account Security
Protect accounts with multi-factor authentication, and understand ReFresh's security architecture.
- Multi-factor authenticationMulti-factor authentication (MFA) adds a second verification step at sign-in, so a stolen password alone is not enough to reach your account. Each person enables MFA on their own account…
- ReFresh security overviewSecurity is built into ReFresh across hosting, encryption, access control, authentication, and monitoring. For certifications, sub-processors, and current audit evidence, see the ReFresh Trust Centre.
Privacy and Data
Where your data is hosted, how ReFresh handles privacy and your data rights, and how to report a security concern.
- Where your data is hosted (data residency)Your organisation's data is region-locked: it is hosted in the region that applies to your organisation and does not move to another region. ReFresh runs regionally and keeps your data…
- Privacy and your data rightsHow ReFresh handles personal and psychosocial-safety data, and where to find your data rights, retention, and privacy contacts. For the full detail, see the ReFresh Trust Centre.
- Reporting a security concernIf you suspect a security vulnerability, data exposure, or other security issue with ReFresh, report it directly to the security team rather than through general support.
