Security
A description of design positions, not a compliance statement.
What this page is and is not
This is a description of how the system is designed, not a compliance statement. We hold no security certification and we are not claiming one. If you need an audited compliance posture today, Creobot is not the right choice yet, and we would rather say that than imply otherwise.
Design positions
You choose every source. Nothing is indexed that you did not add. Removing a source removes its content from the index rather than leaving passages behind that keep answering about things you retired.
Answers are attributed. Each answer shows which source it came from, so a visitor can verify and you can diagnose when something is wrong.
There is a knowledge boundary. Questions outside the indexed content produce a refusal and an escalation path rather than an improvised answer. Account specific questions, commitments and regulated advice are explicitly out of scope.
Data is exportable. Your conversations and question data can be exported.
What is not settled
- Data residency and processing region.
- Encryption specifics in transit and at rest, beyond standard transport security.
- Retention periods.
- Access controls on conversation logs and who can view them internally.
- Incident response and notification commitments.
- Penetration testing.
- Backup and recovery terms.
Reporting a problem
If you find a security issue, contact us directly rather than disclosing it publicly, and we will respond. We do not currently run a bug bounty.
What we would ask a vendor
If you are evaluating this category, the questions worth asking are: which model providers, is provider training disabled and is that contractual, how long is data retained by each party, where is it processed, what is the deletion path end to end, and for any compliance claim, which auditor and which scope. Ask for the answers in writing. We are subject to the same standard.