Security review

The security questionnaire, answered.

Sixteen standard vendor-review questions with direct answers, including the ones where the answer is no. Send this to your reviewer before scheduling a call.

Discuss a controlled pilotRead the trust page

  • No certification claimedAnswers state what is missing
  • Answered by the CTONot a template
  • Pilot scope is written downPublic content only

Vendor review

Answers

What has been audited, and what has not. All five answers here are no, and that is the honest state today.

No. No audit has been performed and there is no report to share. If your review requires one before any pilot, we do not meet that bar today.

No. Creobot is not a business associate, holds no HIPAA attestation, and PHI is out of pilot scope by policy.

No, not today. Signing one without the controls behind it would be worse than declining.

No, neither. There is no scope statement and no assessment.

No external test has been commissioned yet. It is the first item after launch because findings are more useful than a certificate.

Limits

If your review requires more

WHAT WE CANNOT DO YET

We cannot produce a SOC 2 report, sign a BAA, or provide penetration test results, because none of those exist. If your process requires any of them before a pilot, the honest answer is to wait rather than to start a review that will fail at the last step.

What we can do is scope a pilot to public content, run it beside your current assistant, and give your reviewer the data-flow summary and deletion process in writing.

Launch

Still useful without a SOC 2 report

If you can evaluate on public website content, a pilot can start now and your current assistant stays live throughout.