Trust Center
Built to be reviewed, not just described.
Creatrix Campus runs the core academic operations of an institution: student records, faculty evaluation, admissions decisions, accreditation evidence. This page sets out how that data is secured, where it is hosted, who can reach it and what we can evidence, so your review team can assess us on documents rather than adjectives. Anything not covered here, we answer directly.
The ground rules
Three states, used consistently, on every line.
A trust page is only useful if a reviewer can rely on it. Every control below carries one of three states. Nothing is marked as in place unless it exists in the running platform or in a document we can send you.
Running today.
The control is implemented in the platform or the organisation, and we can evidence it during a security review.
Committed and under way.
Work has started or is scheduled. We will give you the target date and the owner rather than a badge.
Exists, shared under NDA.
Certificates, agreements and questionnaire responses are real documents, sent to named reviewers under NDA. If your framework needs an artefact this page does not mention, ask: you will get a direct answer in the first reply.
Independently verified
Certified where it counts, evidenced everywhere else.
Anubavam holds ISO/IEC 27001 and ISO/IEC 27701, both audited by an accredited body and both shared with reviewers on request. Where a framework calls for an artefact we do not hold, we say so at the first meeting rather than at contract stage.
Certified. Our ISMS covers risk assessment, control selection, operations and continual improvement. The certificate and the scope statement are shared on request so your team can confirm the platform is inside the boundary.
Certified. The privacy extension covers our obligations as a processor of personal data, including the controls a GDPR or DPDP reviewer expects to see behind a Data Processing Agreement.
We do not hold a SOC 2 Type 2 report. Institutions that gate on SOC 2 should raise it at the first meeting: our ISO 27001 certificate and scope, internal audit records and questionnaire responses are what we offer in its place, and we will discuss where SOC 2 sits on the compliance roadmap.
The full 321 question instrument is completed and sent to named reviewers on request, because it is the document most United States institutions ask for first. We also answer institution questionnaires directly, section by section.
We complete institution and integrator security questionnaires directly, section by section, including cloud security and third party risk instruments. Completed responses are shared with named reviewers under NDA.
Our security team performs manual application testing, including interception, authentication and session analysis, alongside automated static analysis and secret scanning on every merge request. An independent third party penetration test is on the roadmap.
Governance and people
Security has a named owner and a review cycle.
Buyers ask who is accountable, how policy is maintained, and who is allowed near institutional data. These are the answers.
Where it runs
Where your data lives, and how quickly it comes back.
Creatrix runs as containerised services on Oracle Cloud Infrastructure and Amazon Web Services, with an on-premises deployment option. Recovery targets below are the ones in our runbook, and they are the ones we contract to.
Identity and access
Federated with your identity provider, governed by role.
Access control is where an academic platform earns or loses trust, because roles map to real academic structures: school, programme, cohort, committee. Here is what the platform enforces and what is delegated to your identity provider.
Data protection
Your data is yours, and it moves encrypted.
Ownership, export and encryption are the three questions a legal team asks before a security team asks anything. Here are the answers in the order they are usually asked.
Audit and visibility
Consequential actions are on the record, and you can read them.
Audit logging is one of the strongest parts of the platform, because accreditation evidence depends on it. Administrators review the trail in the product rather than raising a ticket with us.
The platform records data changes with old and new values, permission changes, transaction level activity, login attempts, single sign-on events, API calls and blocked or unauthorised requests. Authorised institutional users review this through an audit log interface in the product, filtered by their access rights.
This is why accreditation evidence is a by-product of daily work rather than a reconstruction exercise: the trail already exists when the panel asks.
Retention periods for each log type are agreed in your contract, and reviewers who need the full audit event catalogue, the retention terms and the log architecture can request them with the security pack.
Request the audit logging overview →
RPT-2026-0142 for candidate F-09231
RPT-2026-0142 · permission change recorded with old and new value
EXP-4471 queued · requester, filters and delivery link recorded
Privacy and regional law
Processor obligations met, in writing.
Our ISO 27701 certification covers the privacy management system behind these commitments, which is the evidence a data protection officer asks for after the agreement itself.
A Data Processing Agreement is available on request. Anubavam acts as processor, your institution as controller, with sub-processors contractually bound to equivalent technical and organisational measures.
The certified privacy information management system is the evidence behind our processor commitments, and the certificate is shared with reviewers on request.
The platform holds education records and supports the access controls and disclosure logging a school official arrangement needs. A FERPA compliance statement and data use agreement is being finalised for United States institutions, and the current draft position is shared on request.
Jurisdiction questions are answered individually today, against the controls in the certified management system. A published matrix mapping those controls to each regional law is being compiled.
Every sub-processor engaged to run the platform is named, with its purpose and region, and is contractually bound to equivalent technical and organisational measures. The current list is in section 11.
Fee and tuition payments are handled through third party gateways and Creatrix does not store card details. A formal scope assessment and the resulting exclusion statement are being documented so the position can be confirmed in writing.
AI governance
AI is administrator controlled, assistive, and logged.
Two thirds of enterprise questionnaires now carry an AI section. This is what the product actually does, who controls it, and where the record of it lives.
Creatrix includes AI assisted features: an assistant and chatbot, recommendations, document and OCR processing, and AI supported reporting. Each of these is enabled or disabled by the institution's administrator, so an institution whose policy prohibits AI on student data can run the platform without them.
Data before models. Governance before automation. Assistance before autonomy.
Governance is catching up with capability deliberately. Alignment to ISO/IEC 42001 and the NIST AI Risk Management Framework, an impact assessment for AI features, a published human in the loop policy for high stakes academic decisions, and a no training clause in the standard agreement are all in progress. Reviewers who need the owner and the target date should ask, and they will get both.
Administrator controlled
AI features, including the assistant and chatbot, are toggled per institution. Nothing turns itself on with a release.
In place
AI activity is logged
AI supported reporting writes to an audit record alongside the platform's other audit trails, so an administrator can see what was generated and when.
In place
Model providers named under NDA
The model provider is configurable per deployment. We name the current provider and version to reviewers under NDA; a public AI transparency page is in progress.
In progress
Governance framework
ISO/IEC 42001 and NIST AI RMF alignment, a named AI governance owner, bias testing and a human in the loop policy for high stakes decisions are being established under the certified management system.
In progress
Build and respond
Every production change passes a security gate.
No engineer deploys directly to production. Changes pass peer and automated review, static analysis and secret scanning before they reach staging, and the security team tests the result.
Sub-processors
Who else touches your data.
These are the sub-processors engaged to deliver the platform itself. Integration services are different: they only receive data if your institution enables that integration.
Accessibility
Raise accessibility early, and we will handle it openly.
Accessibility conformance is a legal procurement requirement for United States public institutions and for EU and UK bodies. We do not yet hold the audited artefact those teams need, so this section states the position plainly rather than claiming a standard we cannot evidence.
Security documentation
Tell us what your review needs, and what it blocks on.
We route requests to the person who owns the answer. If an artefact does not exist, you will hear that in the first reply rather than in week three of the evaluation.
Frequently asked
Plain answers for a security review.
Is Creatrix Campus SOC 2 or ISO 27001 certified?
Anubavam, the company behind Creatrix Campus, holds ISO/IEC 27001 and ISO/IEC 27701 certification. Both certificates, with their scope statements, are shared with reviewers on request.
We do not hold a SOC 2 Type 2 report. Institutions that treat SOC 2 as a hard gate should raise it at the start, and we will discuss the ISO certificate and scope, internal audit records and questionnaire responses we provide in its place.
Have you completed a HECVAT?
HECVAT Full 4.0 is completed and available on request under NDA, because it is the instrument most United States institutions require. We also complete your institution’s own questionnaire directly, section by section, and flag anything that needs discussion before you read it.
Where is our data stored, and can we choose the region?
The platform runs on Oracle Cloud Infrastructure and Amazon Web Services. The hosting region for your tenant is confirmed with the account team and recorded contractually before signature.
Residency is agreed per institution rather than assumed from a map, and an on-premises or private cloud deployment is available where national sovereignty rules require it.
What are your uptime, backup and disaster recovery commitments?
The uptime service level is 99.9%, with regional status published at status.creatrixcampus.net. Backups combine point in time recovery with daily and monthly snapshots, and continuous backup of uploaded files.
Disaster recovery backups are taken every 24 hours to a second availability zone in the same region, giving a recovery point objective of 24 hours and a recovery time objective of 24 to 48 hours.
Do you support single sign-on and multi-factor authentication?
SAML 2.0 single sign-on is supported, along with Active Directory and LDAP integration, so accounts stay governed by your identity provider.
For direct sign-in, two factor authentication uses a one time passcode sent to the registered email address. Institutions requiring authenticator apps or FIDO2 enforce them at their identity provider, which the platform honours through SAML. SCIM provisioning is on the roadmap for very large deployments, and accounts are otherwise managed through the platform and its APIs.
Do you train AI models on our institutional data?
Your data is not used to train third party models as part of the standard service, and AI features are enabled or disabled by your administrator. Institutions whose policy prohibits AI on student data can run the platform with those features off.
Alignment to ISO/IEC 42001 and NIST AI RMF, an impact assessment for AI features, and a no training clause in the standard agreement are all in progress. Reviewers who need the owner and the target date should ask.
Are your products WCAG 2.1 AA conformant, and do you have a VPAT?
Not yet. There is no independently audited WCAG 2.1 AA conformance assessment and no VPAT today. An audit is being commissioned and automated accessibility testing is being added to the build pipeline.
If a VPAT is a procurement requirement for your institution, tell us at the first meeting so it can be handled openly.
How do we report a vulnerability or a live security incident?
Report vulnerabilities to security@anubavam.com with a description, reproduction steps and your contact details. We acknowledge within two business days and we do not pursue good faith researchers who follow this process.
For a live incident affecting your institution, write to incidents@anubavam.com. Confirmed incidents affecting customer data are notified within 72 hours.
The close
Bring us your hardest security questions.
Send the questionnaire. You will get direct answers, named owners and the documents behind them.
