Trust

What Creobot can support today, and what it cannot.

Creobot holds no certifications. Rather than leave you to discover that in a vendor review, this page states the boundary up front and describes the pilot shape that works inside it.

Read the security questionnaireDiscuss a controlled pilot

  • No certification claimedNo SOC 2, HIPAA, ISO or PCI today
  • Public content pilotsApproved public sources only
  • Waitlist openAccess opens in order

Supported

What Creobot can support today

Public website content

Marketing pages, product docs and help centre that anyone can already read.

Approved files

Files you explicitly hand over and approve, held to the same public standard.

Side by side benchmarking

Your current assistant stays live while both answer the same questions.

Deletion on request

Pilot sources and transcripts are removed when you ask, without a ticket queue.

Not claimed

Where Creobot stands on certification

SOC 2 Type I or Type II

No audit has been performed. There is no report.

HIPAA compliance or a BAA

Creobot is not a business associate and will not sign one today.

ISO 27001 or PCI DSS

No certification, no assessment, no scope statement.

Penetration test results

No external test has been commissioned yet.

Retention or training guarantees

The model provider mix is not final, so no durable guarantee can be made about retention or training across it.

GDPR certification

There is no such thing as GDPR certification for a product, and no vendor should offer you one. A DPA is a separate matter and is drafted.

WHY THIS IS ON THE PAGE

A buyer who finds a certification gap themselves stops trusting everything else on the site. Stating it first is cheaper than being caught by it, and it lets the rest of this page be specific rather than defensive.

Pilot rules

Public-content pilot rules

Only content a visitor could already read

Public pages, public docs, public help centre. If a URL needs a login, it is out of scope.

Files are approved one list at a time

You see the source list before anything is indexed, and you approve it.

No customer data of any kind

No PII, no PHI, no payment data, no credentials, no confidential legal content, no internal private documents.

Your current assistant stays live

A pilot runs beside what you have. Nothing is switched off to test us.

Deletion is part of the pilot, not an escalation

Sources and transcripts are removed on request as a normal step.

Controlled pilot

Customer-controlled pilot

For teams that like Creobot but cannot approve a new uncertified SaaS yet, we can discuss a pilot where the scope, accounts and data handling are limited from day one.

WHAT THIS IS AND IS NOT

This is a narrower pilot shape, not a certification. It does not make Creobot compliant, it does not transfer any vendor's attestation to us, and it is not a substitute for the SOC 2 report your reviewer is asking for. It is a way to evaluate answer quality on a limited surface while that report does not exist.

For your reviewer

Security review pack

Security questionnaire

Answered plainly, including the answers that are no.

Data-flow summary

Where content goes, which provider sees it, and what is stored.

Pilot rules and scope

What may enter a pilot, written down rather than agreed verbally.

Deletion process

How to request removal and what it covers.

Subprocessor status

Who is in the chain today and what is still moving.

What changes before paid rollout

The list of things that must be true before anyone is charged.

Chain of trust

Vendor controls, and why they are not ours

Creobot runs on infrastructure and model providers that hold their own certifications. Those are their attestations covering their systems.

THIS DOES NOT TRANSFER

A provider's attestation covers their systems and does not extend to Creobot, which holds no such report. Any vendor implying otherwise is misleading you. Creobot's own controls have not been audited by anyone. The subprocessor list is published so you can assess the chain yourself rather than take a badge on trust.

Roadmap

Certification roadmap

Before paid rollout

Signed DPA, published subprocessor list, retention periods stated, and a documented deletion process.

After launch, in order of demand

External penetration test first, because it produces findings we can act on, rather than a report we can show.

SOC 2 when it is real

A Type II observation window cannot be shortened by wanting it. We will name a date when the window opens, not before.

What we will not do

Announce an audit in progress as though it were complete, or use a provider's badge as our own.

Not yet

Who should wait

Healthcare workflows touching PHI

No BAA, so a pilot cannot be lawful for you today.

Payment and card workflows

No PCI scope, and card data is out of pilot scope by policy.

Banking and regulated finance

Vendor review will ask for a SOC 2 report that does not exist yet.

Confidential legal workflows

Privileged material should not enter a pilot with an uncertified vendor.

Procurement requiring SOC 2 before any pilot

That is a reasonable policy and we do not meet it today.

THIS IS QUALIFICATION, NOT WEAKNESS

Selling into these workflows today would waste your review cycle and ours. When the report exists, the conversation changes and we will say so.

Trust questions

No. There is no audit and no report. Early pilots are scoped around public website content because of that.

No. Their attestation covers their systems, not Creobot's. Anyone telling you otherwise is misreading the report.

Yes. That is the default shape and the one we recommend.

Yes, and we prefer it. A side by side benchmark is more useful than a replacement you cannot compare against.

A DPA is drafted and is published before anyone is charged. It has not been through your counsel or ours in final form.

It is deleted on request as a normal step, not an escalation. If you do not ask, sources and transcripts remain until the pilot closes.

The model provider mix is not final, so no durable guarantee can be made across it. That is why pilots are public content: nothing enters that a visitor could not already read.

When you need SOC 2 or a BAA before any pilot, wait. If you can evaluate on public content, there is nothing to wait for.

Launch

Send this to your security reviewer

The questionnaire answers the standard vendor review questions, including the ones where the answer is no.