Security

Design positions, and what is not settled.

This page describes how data moves and what we intend, and it separates that from what is actually settled. Nothing here is an audited control, because there has been no audit.

Where content and questions movePages are indexed, questions and retrieved passages go to a model provider, and the answer is stored in a transcript.Your pagesIndexModel providerAnswerTranscript storeLEAVES YOUR CONTROLFive movements. The dashed box is the one that crosses a boundary you do not own.

Where Creobot stands on certification

Stated plainly, so you can screen us accurately: Creobot holds no security certification. No SOC 2, HIPAA, ISO 27001, PCI DSS or compliance with any named framework. No zero-retention guarantee, no guarantee that submitted data is never used for model training, and no committed processing region while the model provider mix is still being settled.

We would rather lose a badge screen than make a claim that does not survive the first question about which auditor and which scope.

This is why the first engagement is designed to need none of it. A public-content benchmark runs on your public website pages, docs, help content and sources you approve, so you can measure answer quality, source grounding and handoff before any security review starts. If your process requires a report before any pilot at all, we are a later-stage fit and will tell you that directly rather than run you through a questionnaire that ends in the same place.

Where your data moves

Five movements, and most data maps miss at least two of them.

Your pages are read and the text extracted. That text is split, embedded and stored in an index. At question time, the retrieved passages and the visitor's question are sent to a model provider. The answer comes back and is stored in a transcript alongside the question. Any error monitoring in the path may see fragments of the above, which is the copy people consistently forget.

The third movement is the one that crosses a boundary we do not control, and it is the one worth asking every vendor about, including us.

Design positions

Conversation data belongs to the site owner

That is the position, and it will be in the terms before anyone is charged.

Content is stored, not trained on

Your pages become retrievable passages. They are not used to train any model by us.

Redaction happens at write time

Not at read time. Read time redaction means the raw value was stored and merely hidden.

The subprocessor list will be current

It names every party in the processing chain, and it is maintained rather than written once.

What is not settled

Retention periods

How long transcripts, captured details and derived analytics are each kept.

Processing region

Whether a region can be chosen at all, and which ones.

The subprocessor list

The model provider mix is still moving, so the list is not final.

Incident response and notification

What we commit to, and in what timeframe.

Backup and recovery terms

How often data is backed up, how long backups are held, and the recovery target if something is lost.

All five are published before paid rollout. Naming a number now would be naming one we might have to revise, and a revised security commitment is worse than a late one.

Security questions

No. Creobot holds no security certification and we are not claiming one. Naming a framework we have not been audited against would be a false claim, and it is the fastest way to make a technical buyer distrust everything else on the page.

Your content is stored as retrievable passages. It is not used to train anything by us. Whether a model provider retains prompt data depends on that provider's terms, which we will name on the subprocessor list rather than summarise into a claim we cannot stand behind.

To a model provider, along with the passages retrieved from your own content, so an answer can be produced. That is the one movement that crosses a boundary we do not control, and it is drawn explicitly in the diagram above.

Not today. A data processing agreement is planned before paid rollout. We would rather say that than point you at an unsigned template and let you assume it is in force.

Retention periods will be published before anyone is charged. They are not settled, and a number invented now would be a number we might have to revise.

Retention periods, a current subprocessor list, incident response and notification commitments, and backup and recovery terms. That is the minimum before it is reasonable to charge for this.

Through the contact page, marked as a security issue. It reaches the people building the product rather than a triage queue.

Trust

Something not covered here?

Ask directly. Security questions are answered by the people building the product, and we would rather tell you what is unsettled than let you assume.