Security review
The security questionnaire, answered.
Sixteen standard vendor-review questions with direct answers, including the ones where the answer is no. Send this to your reviewer before scheduling a call.
- No certification claimedAnswers state what is missing
- Answered by the CTONot a template
- Pilot scope is written downPublic content only
Vendor review
Answers
What has been audited, and what has not. All five answers here are no, and that is the honest state today.
No. No audit has been performed and there is no report to share. If your review requires one before any pilot, we do not meet that bar today.
No. Creobot is not a business associate, holds no HIPAA attestation, and PHI is out of pilot scope by policy.
No, not today. Signing one without the controls behind it would be worse than declining.
No, neither. There is no scope statement and no assessment.
No external test has been commissioned yet. It is the first item after launch because findings are more useful than a certificate.
What may enter a pilot, what may not, and what happens to it afterwards.
Public website pages, public product docs, public help centre content, and files you explicitly approve. The test is whether a visitor could already read it.
Customer records and PII, PHI, payment or card data, credentials, confidential legal content, and internal private documents. This is policy, not a default you can override.
Yes, on request, as a normal step rather than an escalation. It covers indexed sources and stored transcripts.
The provider mix is not final, so no durable guarantee can be made across it. Pilots are scoped to public content so that the question does not carry the same weight.
Yes. That is the default and the recommended shape.
Who can reach pilot data, and which third parties are involved.
The two founders. There is no support organisation, no offshore team and no contractor pool, because the company is two people.
Hosting and model providers. The list is published on the subprocessors page and the model provider mix is still moving, which is stated there rather than smoothed over.
What can be signed today, what changes before anyone is charged, and who answers for it.
A DPA is drafted and published before anyone is charged. It is not yet in final reviewed form.
Yes. We prefer it, because a side by side comparison is worth more than a replacement you cannot measure against.
Signed DPA, published subprocessor list, stated retention periods and a documented deletion process. Those are the minimum, not the roadmap.
Vishal Chiniwar, co-founder and CTO. The answers above are his, not a template.
Limits
If your review requires more
WHAT WE CANNOT DO YET
We cannot produce a SOC 2 report, sign a BAA, or provide penetration test results, because none of those exist. If your process requires any of them before a pilot, the honest answer is to wait rather than to start a review that will fail at the last step.
What we can do is scope a pilot to public content, run it beside your current assistant, and give your reviewer the data-flow summary and deletion process in writing.
Launch
Still useful without a SOC 2 report
If you can evaluate on public website content, a pilot can start now and your current assistant stays live throughout.