Legal
Information security and data management policy
What may go into a pilot, what must not, and exactly where Creobot stands on certification. Written to be screened against, not to reassure.
Effective 31 August 2026. Creoglyph Technologies Private Limited.
Scope
What this covers
This policy covers the Creobot product and the Creoglyph website that sells it, during the pilot period. Every engagement today is a scoped pilot run with a person on our side.
Allowed
What may go into a pilot
Public website pages
Marketing pages, documentation, help centre articles, pricing pages and anything else already served to anonymous visitors.
Documents you explicitly approve
A PDF or export you nominate. Approval is per-source and recorded, not blanket.
Questions you supply
The test set for a benchmark. These are questions, not customer conversations.
Prohibited
What must not be sent
Customer records of any kind
Names, contact details, order history, support transcripts belonging to your customers.
Health, payment or government identity data
Creobot offers no BAA, is not PCI scoped, and must not receive this category under any pilot.
Credentials and secrets
API keys, passwords, tokens, internal URLs behind authentication.
Anything under a confidentiality obligation you hold
If you are not sure whether a source qualifies, leave it out and ask.
If prohibited data reaches us anyway, tell us and we will delete it and confirm in writing.
Public content
The public-content pilot
Creobot is not SOC 2 certified. That is exactly why the first engagement is scoped to public content: it lets you measure answer quality, source grounding and handoff before a security review is needed at all. It is a deliberate design of the engagement, not a workaround.
Nothing behind a login
If an anonymous visitor cannot reach it, it is out of scope for a first benchmark.
Your current assistant stays live
Nothing is switched off and nothing is installed on your site to run a benchmark.
Access
Access control and data minimisation
Two people
Creoglyph is Sachin and Vishal. Pilot material is accessible to us and to the infrastructure providers listed under subprocessors. There is no wider staff.
We ask for the least that answers the question
A benchmark needs a public URL and a question set. It does not need an account, an integration or a data export, so we do not ask for them.
Named scope on request
A customer-controlled pilot fixes sources, accounts, access and a deletion trigger in writing before anything runs. See the pilot options.
Retention
Storage, retention and deletion
Retention periods are not final
the model provider mix is not settled, so we do not publish a retention number we would have to change. This is stated rather than hidden.
Deletion on request
Ask at business@creoglyph.com and we remove pilot content and confirm. Deletion includes the vector index, not only the source files — an index left in place is not a deletion.
Form submissions
Contact and demo submissions become email. They are covered by the privacy statement.
Subprocessors
Who else is involved
A model provider processes the retrieved passages and the visitor question at answer time. Hosting and form delivery are third-party services. The complete list is not published yet, and an incomplete list is more misleading than none, so the subprocessors page says so plainly and will be filled in before anyone is charged.
Incidents
If something goes wrong
Contact
business@creoglyph.com, subject line "security". Confirmed the same working day.
What you get
What happened, what data was in scope, what we did, and when. If we do not know something yet we say that rather than estimate.
No bug bounty yet
There is no paid programme. Reports are still welcome and still answered.
Certification
Where Creobot stands on certification
Stated plainly so you can screen us accurately. Creobot holds no SOC 2 Type I or Type II report, no ISO 27001 certification, no HIPAA attestation or BAA, and no PCI DSS assessment. No external penetration test has been commissioned. There is no such thing as GDPR certification for a product and we do not imply one. We make no zero-retention guarantee and no guarantee that submitted content is never used for model training, because the provider mix is not final.
A vendor's certification is theirs, not ours. Where a model provider or host holds a report, that covers their service and says nothing about Creobot.
Teams whose process requires an audit report before any pilot at all are a later-stage fit, and we will say so on the first call rather than run you through a questionnaire that ends in the same place. The security questionnaire answers sixteen procurement questions directly.
Questions about any of this?
A policy that cannot be questioned is not a policy. Ask and one of us answers, usually the same day.