Trust
What Creobot can support today, and what it cannot.
Creobot holds no certifications. Rather than leave you to discover that in a vendor review, this page states the boundary up front and describes the pilot shape that works inside it.
- No certification claimedNo SOC 2, HIPAA, ISO or PCI today
- Public content pilotsApproved public sources only
- Waitlist openAccess opens in order
Supported
What Creobot can support today
Public website content
Marketing pages, product docs and help centre that anyone can already read.
Approved files
Files you explicitly hand over and approve, held to the same public standard.
Side by side benchmarking
Your current assistant stays live while both answer the same questions.
Deletion on request
Pilot sources and transcripts are removed when you ask, without a ticket queue.
Not claimed
Where Creobot stands on certification
SOC 2 Type I or Type II
No audit has been performed. There is no report.
HIPAA compliance or a BAA
Creobot is not a business associate and will not sign one today.
ISO 27001 or PCI DSS
No certification, no assessment, no scope statement.
Penetration test results
No external test has been commissioned yet.
Retention or training guarantees
The model provider mix is not final, so no durable guarantee can be made about retention or training across it.
GDPR certification
There is no such thing as GDPR certification for a product, and no vendor should offer you one. A DPA is a separate matter and is drafted.
WHY THIS IS ON THE PAGE
A buyer who finds a certification gap themselves stops trusting everything else on the site. Stating it first is cheaper than being caught by it, and it lets the rest of this page be specific rather than defensive.
Pilot rules
Public-content pilot rules
Only content a visitor could already read
Public pages, public docs, public help centre. If a URL needs a login, it is out of scope.
Files are approved one list at a time
You see the source list before anything is indexed, and you approve it.
No customer data of any kind
No PII, no PHI, no payment data, no credentials, no confidential legal content, no internal private documents.
Your current assistant stays live
A pilot runs beside what you have. Nothing is switched off to test us.
Deletion is part of the pilot, not an escalation
Sources and transcripts are removed on request as a normal step.
Controlled pilot
Customer-controlled pilot
For teams that like Creobot but cannot approve a new uncertified SaaS yet, we can discuss a pilot where the scope, accounts and data handling are limited from day one.
WHAT THIS IS AND IS NOT
This is a narrower pilot shape, not a certification. It does not make Creobot compliant, it does not transfer any vendor's attestation to us, and it is not a substitute for the SOC 2 report your reviewer is asking for. It is a way to evaluate answer quality on a limited surface while that report does not exist.
For your reviewer
Security review pack
Security questionnaire
Answered plainly, including the answers that are no.
Data-flow summary
Where content goes, which provider sees it, and what is stored.
Pilot rules and scope
What may enter a pilot, written down rather than agreed verbally.
Deletion process
How to request removal and what it covers.
Subprocessor status
Who is in the chain today and what is still moving.
What changes before paid rollout
The list of things that must be true before anyone is charged.
Chain of trust
Vendor controls, and why they are not ours
Creobot runs on infrastructure and model providers that hold their own certifications. Those are their attestations covering their systems.
THIS DOES NOT TRANSFER
A provider's attestation covers their systems and does not extend to Creobot, which holds no such report. Any vendor implying otherwise is misleading you. Creobot's own controls have not been audited by anyone. The subprocessor list is published so you can assess the chain yourself rather than take a badge on trust.
Roadmap
Certification roadmap
Before paid rollout
Signed DPA, published subprocessor list, retention periods stated, and a documented deletion process.
After launch, in order of demand
External penetration test first, because it produces findings we can act on, rather than a report we can show.
SOC 2 when it is real
A Type II observation window cannot be shortened by wanting it. We will name a date when the window opens, not before.
What we will not do
Announce an audit in progress as though it were complete, or use a provider's badge as our own.
Not yet
Who should wait
Healthcare workflows touching PHI
No BAA, so a pilot cannot be lawful for you today.
Payment and card workflows
No PCI scope, and card data is out of pilot scope by policy.
Banking and regulated finance
Vendor review will ask for a SOC 2 report that does not exist yet.
Confidential legal workflows
Privileged material should not enter a pilot with an uncertified vendor.
Procurement requiring SOC 2 before any pilot
That is a reasonable policy and we do not meet it today.
THIS IS QUALIFICATION, NOT WEAKNESS
Selling into these workflows today would waste your review cycle and ours. When the report exists, the conversation changes and we will say so.
Trust questions
Launch
Send this to your security reviewer
The questionnaire answers the standard vendor review questions, including the ones where the answer is no.