Legal

Information security and data management policy

What may go into a pilot, what must not, and exactly where Creobot stands on certification. Written to be screened against, not to reassure.

Ask about thisTrust centre

stated plainlyINFORMATION SECURITYPublic website contentDocs and approved sourcesCustomer recordsPayment or health datawhat holdswhat does noteffective date shownplain-language firstno badges
In short. Public website content and sources you approve may go into a pilot. Customer records, health, payment and credential data must not. Creobot holds no SOC 2, ISO 27001, HIPAA or PCI certification, and that is why the first benchmark needs none of your private data.
Effective 31 August 2026. Creoglyph Technologies Private Limited.

Scope

What this covers

This policy covers the Creobot product and the Creoglyph website that sells it, during the pilot period. Every engagement today is a scoped pilot run with a person on our side.

Allowed

What may go into a pilot

Public website pages

Marketing pages, documentation, help centre articles, pricing pages and anything else already served to anonymous visitors.

Documents you explicitly approve

A PDF or export you nominate. Approval is per-source and recorded, not blanket.

Questions you supply

The test set for a benchmark. These are questions, not customer conversations.

Prohibited

What must not be sent

Customer records of any kind

Names, contact details, order history, support transcripts belonging to your customers.

Health, payment or government identity data

Creobot offers no BAA, is not PCI scoped, and must not receive this category under any pilot.

Credentials and secrets

API keys, passwords, tokens, internal URLs behind authentication.

Anything under a confidentiality obligation you hold

If you are not sure whether a source qualifies, leave it out and ask.

If prohibited data reaches us anyway, tell us and we will delete it and confirm in writing.

Public content

The public-content pilot

Creobot is not SOC 2 certified. That is exactly why the first engagement is scoped to public content: it lets you measure answer quality, source grounding and handoff before a security review is needed at all. It is a deliberate design of the engagement, not a workaround.

Nothing behind a login

If an anonymous visitor cannot reach it, it is out of scope for a first benchmark.

Your current assistant stays live

Nothing is switched off and nothing is installed on your site to run a benchmark.

Access

Access control and data minimisation

Two people

Creoglyph is Sachin and Vishal. Pilot material is accessible to us and to the infrastructure providers listed under subprocessors. There is no wider staff.

We ask for the least that answers the question

A benchmark needs a public URL and a question set. It does not need an account, an integration or a data export, so we do not ask for them.

Named scope on request

A customer-controlled pilot fixes sources, accounts, access and a deletion trigger in writing before anything runs. See the pilot options.

Retention

Storage, retention and deletion

Retention periods are not final

the model provider mix is not settled, so we do not publish a retention number we would have to change. This is stated rather than hidden.

Deletion on request

Ask at business@creoglyph.com and we remove pilot content and confirm. Deletion includes the vector index, not only the source files — an index left in place is not a deletion.

Form submissions

Contact and demo submissions become email. They are covered by the privacy statement.

Subprocessors

Who else is involved

A model provider processes the retrieved passages and the visitor question at answer time. Hosting and form delivery are third-party services. The complete list is not published yet, and an incomplete list is more misleading than none, so the subprocessors page says so plainly and will be filled in before anyone is charged.

Incidents

If something goes wrong

Contact

business@creoglyph.com, subject line "security". Confirmed the same working day.

What you get

What happened, what data was in scope, what we did, and when. If we do not know something yet we say that rather than estimate.

No bug bounty yet

There is no paid programme. Reports are still welcome and still answered.

Certification

Where Creobot stands on certification

Stated plainly so you can screen us accurately. Creobot holds no SOC 2 Type I or Type II report, no ISO 27001 certification, no HIPAA attestation or BAA, and no PCI DSS assessment. No external penetration test has been commissioned. There is no such thing as GDPR certification for a product and we do not imply one. We make no zero-retention guarantee and no guarantee that submitted content is never used for model training, because the provider mix is not final.

A vendor's certification is theirs, not ours. Where a model provider or host holds a report, that covers their service and says nothing about Creobot.

Teams whose process requires an audit report before any pilot at all are a later-stage fit, and we will say so on the first call rather than run you through a questionnaire that ends in the same place. The security questionnaire answers sixteen procurement questions directly.

Questions about any of this?

A policy that cannot be questioned is not a policy. Ask and one of us answers, usually the same day.