Trust Center

Built to be reviewed, not just described.

Creatrix Campus runs the core academic operations of an institution: student records, faculty evaluation, admissions decisions, accreditation evidence. This page sets out how that data is secured, where it is hosted, who can reach it and what we can evidence, so your review team can assess us on documents rather than adjectives. Anything not covered here, we answer directly.

Maintained by the Anubavam security and compliance team Every claim traceable to a certificate, a contract or a running system
01 · How to read this page

The ground rules

Three states, used consistently, on every line.

A trust page is only useful if a reviewer can rely on it. Every control below carries one of three states. Nothing is marked as in place unless it exists in the running platform or in a document we can send you.

In place

Running today.

The control is implemented in the platform or the organisation, and we can evidence it during a security review.

In progress

Committed and under way.

Work has started or is scheduled. We will give you the target date and the owner rather than a badge.

On request

Exists, shared under NDA.

Certificates, agreements and questionnaire responses are real documents, sent to named reviewers under NDA. If your framework needs an artefact this page does not mention, ask: you will get a direct answer in the first reply.

02 · Certifications and independent assessment

Independently verified

Certified where it counts, evidenced everywhere else.

Anubavam holds ISO/IEC 27001 and ISO/IEC 27701, both audited by an accredited body and both shared with reviewers on request. Where a framework calls for an artefact we do not hold, we say so at the first meeting rather than at contract stage.

Information security standardISO/IEC 27001Information Security Management System

Certified. Our ISMS covers risk assessment, control selection, operations and continual improvement. The certificate and the scope statement are shared on request so your team can confirm the platform is inside the boundary.

CertifiedCertificate on request
Privacy information standardISO/IEC 27701PIMS, extends ISO 27001 with privacy

Certified. The privacy extension covers our obligations as a processor of personal data, including the controls a GDPR or DPDP reviewer expects to see behind a Data Processing Agreement.

CertifiedCertificate on request
Operating effectiveness auditSOC 2 Type 2Not held. ISO evidence offered

We do not hold a SOC 2 Type 2 report. Institutions that gate on SOC 2 should raise it at the first meeting: our ISO 27001 certificate and scope, internal audit records and questionnaire responses are what we offer in its place, and we will discuss where SOC 2 sits on the compliance roadmap.

On requestISO evidence offered in its place
Higher education questionnaireHECVAT Full 4.0EDUCAUSE, Internet2, REN-ISAC

The full 321 question instrument is completed and sent to named reviewers on request, because it is the document most United States institutions ask for first. We also answer institution questionnaires directly, section by section.

On requestShared under NDA
Institution questionnairesYour own templateCloud security and third party risk

We complete institution and integrator security questionnaires directly, section by section, including cloud security and third party risk instruments. Completed responses are shared with named reviewers under NDA.

On requestAnswered under NDA
Security testingApplication security testingInternal team, plus pipeline automation

Our security team performs manual application testing, including interception, authentication and session analysis, alongside automated static analysis and secret scanning on every merge request. An independent third party penetration test is on the roadmap.

In placeInternal testing in place
Where a certificate does not exist, no badge appears. Reviewers who need a specific artefact should write to compliance@anubavam.com with the framework and the deadline, and we will tell you what we can and cannot supply. Request documentation →
03 · Governance and people

Governance and people

Security has a named owner and a review cycle.

Buyers ask who is accountable, how policy is maintained, and who is allowed near institutional data. These are the answers.

Security accountabilityDesignated CISO
Security is owned by a designated CISO with a defined governance structure, not distributed informally across IT.
In place
Information security policyReviewed annually
A documented information security policy is maintained and reviewed annually, sitting under the certified ISO 27001 management system.
In place
Internal auditQuarterly
Internal security audits run quarterly. Findings are tracked to closure and feed the ISO surveillance cycle.
In place
Background screeningAccredited BGV provider
Staff are screened through an accredited provider covering identity, address, education and employment history, under NDA and contract. The provider destroys screening data after six months.
In place
Security awareness trainingAt onboarding
Security training is delivered when a person joins, under the certified ISO 27001 management system. A tracked annual refresh with completion reporting is being added.
Refresh cycle in progress
Support access to your dataCustomer approved
Support does not need routine access to institutional data. Investigations are run screen share first with your team driving, and where data access is unavoidable it is requested and approved by you. Masked or sanitised data is used for debugging wherever possible.
In place
04 · Hosting, residency and resilience

Where it runs

Where your data lives, and how quickly it comes back.

Creatrix runs as containerised services on Oracle Cloud Infrastructure and Amazon Web Services, with an on-premises deployment option. Recovery targets below are the ones in our runbook, and they are the ones we contract to.

Deployment modelSaaS · private cloud · on-premises
Containerised services orchestrated with Kubernetes, published from a private image registry. On-premises and private cloud deployments are supported for institutions with sovereignty requirements.
In place
Cloud providersOCI · AWS
Infrastructure and storage run on Oracle Cloud Infrastructure and AWS, inheriting their certified physical and platform controls. Amazon SES is used for transactional email where enabled.
In place
Data residencyConfirmed per tenant
The hosting region for your tenant is confirmed with the account team and recorded contractually before signature. Residency is answered per institution, so the region, the backups and the recovery copies are agreed in writing rather than assumed from a map.
Contractual
Tenant isolationInstitution scoped
Every tenant scoped record carries its institution identifier, and module availability is controlled per institution. Deployment patterns include separate databases per institution, and the isolation architecture is walked through with your architects during review.
In place
Uptime commitment99.9%
A 99.9% uptime service level with regional status published at status.creatrixcampus.net. Service credits are set in the commercial agreement.
In place
BackupsPITR · snapshots
Point in time recovery plus snapshot backups: the two most recent daily snapshots and the two most recent monthly snapshots are retained, with continuous backup of user uploaded files.
In place
Disaster recoveryRPO 24h · RTO 24 to 48h
A disaster recovery backup is taken every 24 hours to a second availability zone in the same region. Recovery point objective 24 hours, recovery time objective 24 to 48 hours. Tighter targets are discussed case by case where an institution needs them.
Committed
Security monitoringCentralised logging
Application, API, authentication and blocked request events are captured and shipped to a centralised search and logging stack, which is what makes an incident reconstructable after the fact.
In place
05 · Identity and access

Identity and access

Federated with your identity provider, governed by role.

Access control is where an academic platform earns or loses trust, because roles map to real academic structures: school, programme, cohort, committee. Here is what the platform enforces and what is delegated to your identity provider.

Single sign-onSAML 2.0
SAML 2.0 single sign-on is implemented, with Active Directory and LDAP integration and configurable identity provider endpoints. A published list of tested identity providers is in preparation.
In place
Multi-factor authenticationEmail OTP · IdP delegation
For direct username and password sign-in, a one time passcode sent to the registered email address is supported. Institutions that require authenticator apps, FIDO2 or push approval enforce them at their identity provider, which the platform honours through SAML. Native authenticator app support is on the roadmap.
In place via your IdP
Role based access controlRBAC
Granular role, group, module, menu and function level permissions, with custom permission overrides and role based IP restrictions. Attribute based rules exist contextually but are not yet documented as a formal ABAC model.
In place
Provisioning and deprovisioningPlatform and API
Accounts are created, updated and deactivated through the platform and its APIs, and are governed by your identity provider at sign-in. SCIM support is on the roadmap for very large deployments.
SCIM on the roadmap
Session managementServer side · device aware
Server side sessions with distributed session handling, access and refresh token lifecycles, device tracking and last access timestamps. An administrator facing policy screen for idle timeout and concurrent session limits is in progress.
Implemented, policy controls in progress
Password policyAdmin configurable
Administrators configure minimum length, character class requirements, expiry period and password history so previous passwords cannot be reused.
In place
Privileged and production accessPipeline gated
Production changes go through a mandatory merge request and a CI pipeline: engineers do not deploy directly. Privileged access management tooling and just in time elevation are on the security roadmap.
In place
06 · Data protection and encryption

Data protection

Your data is yours, and it moves encrypted.

Ownership, export and encryption are the three questions a legal team asks before a security team asks anything. Here are the answers in the order they are usually asked.

Data ownershipInstitution owns
The institution owns all data uploaded to or generated by the platform. Anubavam is the processor, your institution is the controller, and we use your data only to deliver the contracted service.
In place
Data export and portabilityPrivileged users
Privileged users export data from the product: smaller extracts download immediately, large volume exports are processed asynchronously and delivered through a secure link. Every export is audit logged with requester, filters and timestamp.
In place
Encryption in transitTLS 1.2 and 1.3
All traffic uses TLS 1.2 or TLS 1.3, including database connections, which are certificate authenticated. Verification of legacy protocol disablement at the edge, plus HSTS, is part of the current hardening work.
In place
Encryption at restAES
Application level AES encryption protects sensitive fields and parameters. A programme to extend AES-256 across every store, including database tablespace encryption for student personal data, is under way and tracked as a prioritised roadmap item.
In progress
Key custody optionsOn-premises · private cloud
Where a regulator or sovereign requirement calls for the institution to hold its own key material, the on-premises or private cloud deployment is the route we offer today. Managed key custody in the SaaS tenant is on the roadmap.
On-premises today
Retention and deletionPolicy
Retention is agreed contractually per institution, and secure deletion at contract end is handled under those terms. A retention schedule by data category is being formalised so it can be published rather than negotiated each time.
In progress
Data classificationTaxonomy
Access to sensitive records is already controlled by role, module and function. A four tier classification (public, internal, confidential, restricted) mapped across platform data is being formalised on top of those controls.
In progress
07 · Audit and customer visibility

Audit and visibility

Consequential actions are on the record, and you can read them.

Audit logging is one of the strongest parts of the platform, because accreditation evidence depends on it. Administrators review the trail in the product rather than raising a ticket with us.

The platform records data changes with old and new values, permission changes, transaction level activity, login attempts, single sign-on events, API calls and blocked or unauthorised requests. Authorised institutional users review this through an audit log interface in the product, filtered by their access rights.

This is why accreditation evidence is a by-product of daily work rather than a reconstruction exercise: the trail already exists when the panel asks.

Retention periods for each log type are agreed in your contract, and reviewers who need the full audit event catalogue, the retention terms and the log architecture can request them with the security pack.

Audit log review is part of administrator handover and training.
Request the audit logging overview →
Illustrative entries · shape of the record
2026-05-12 09:18:42 Dean of Engineering · SAML sign-on Opened promotion case RPT-2026-0142 for candidate F-09231
2026-05-12 11:02:09 Faculty Affairs administrator Changed reviewer assignment on RPT-2026-0142 · permission change recorded with old and new value
2026-05-12 14:40:51 Registry data export Export request EXP-4471 queued · requester, filters and delivery link recorded
08 · Privacy and regional law

Privacy and regional law

Processor obligations met, in writing.

Our ISO 27701 certification covers the privacy management system behind these commitments, which is the evidence a data protection officer asks for after the agreement itself.

GDPR
European Union
In place

A Data Processing Agreement is available on request. Anubavam acts as processor, your institution as controller, with sub-processors contractually bound to equivalent technical and organisational measures.

ISO 27701
Privacy management
Certified

The certified privacy information management system is the evidence behind our processor commitments, and the certificate is shared with reviewers on request.

FERPA
United States
In progress

The platform holds education records and supports the access controls and disclosure logging a school official arrangement needs. A FERPA compliance statement and data use agreement is being finalised for United States institutions, and the current draft position is shared on request.

Regional law
PDPA · DPDP · PDPL · DIFC · POPIA
Answered per jurisdiction

Jurisdiction questions are answered individually today, against the controls in the certified management system. A published matrix mapping those controls to each regional law is being compiled.

Sub-processors
Named and contracted
In place

Every sub-processor engaged to run the platform is named, with its purpose and region, and is contractually bound to equivalent technical and organisational measures. The current list is in section 11.

PCI DSS
Payments
Scope assessment

Fee and tuition payments are handled through third party gateways and Creatrix does not store card details. A formal scope assessment and the resulting exclusion statement are being documented so the position can be confirmed in writing.

Privacy questions go to a named inbox. Data subject requests, DPA negotiation and jurisdiction questions: dpo@anubavam.com. Contract and clause negotiation: legal@anubavam.com. Request the DPA →
09 · AI governance

AI governance

AI is administrator controlled, assistive, and logged.

Two thirds of enterprise questionnaires now carry an AI section. This is what the product actually does, who controls it, and where the record of it lives.

Creatrix includes AI assisted features: an assistant and chatbot, recommendations, document and OCR processing, and AI supported reporting. Each of these is enabled or disabled by the institution's administrator, so an institution whose policy prohibits AI on student data can run the platform without them.

Data before models. Governance before automation. Assistance before autonomy.

Governance is catching up with capability deliberately. Alignment to ISO/IEC 42001 and the NIST AI Risk Management Framework, an impact assessment for AI features, a published human in the loop policy for high stakes academic decisions, and a no training clause in the standard agreement are all in progress. Reviewers who need the owner and the target date should ask, and they will get both.

01

Administrator controlled

AI features, including the assistant and chatbot, are toggled per institution. Nothing turns itself on with a release.

In place

02

AI activity is logged

AI supported reporting writes to an audit record alongside the platform's other audit trails, so an administrator can see what was generated and when.

In place

03

Model providers named under NDA

The model provider is configurable per deployment. We name the current provider and version to reviewers under NDA; a public AI transparency page is in progress.

In progress

04

Governance framework

ISO/IEC 42001 and NIST AI RMF alignment, a named AI governance owner, bias testing and a human in the loop policy for high stakes decisions are being established under the certified management system.

In progress

10 · Secure development, vulnerabilities and incidents

Build and respond

Every production change passes a security gate.

No engineer deploys directly to production. Changes pass peer and automated review, static analysis and secret scanning before they reach staging, and the security team tests the result.

Change controlMandatory merge requests
All production changes go through a merge request with peer and automated review, validation jobs, and staged deployment from staging to production. Draft branches cannot auto merge, and the pipeline cancels on failure.
In place
Static analysisSAST
Static application security testing runs on every merge request across backend and frontend code.
In place
Secret scanningPipeline
Automated secret detection runs on changed files in every merge request, preventing credentials from entering the codebase.
In place
Manual application testingSecurity team
The security team performs manual web application testing: request interception, authentication and session analysis, input validation and verification of reported findings, focused on high risk modules and major releases.
In place
Expanding the pipelineSCA · DAST · image scanning
Dynamic testing against staging, software composition analysis with CVE alerting and container image scanning are the next gates being added, alongside the static analysis and secret scanning already running.
In progress
Remediation targetsSeverity based
Findings are tracked as security defects with owners. Remediation windows per severity tier are being formalised, and the current working targets are shared with reviewers on request rather than quoted here as industry defaults.
In progress
Incident responseTested annually
An incident response plan exists and is tested annually, with runbooks being extended to cover every incident category.
Tested annually
Breach notification72 hours
Affected customers are notified within 72 hours of a confirmed incident, through the designated institutional contact. Report a suspected incident to incidents@anubavam.com.
Committed
Responsible disclosuresecurity@anubavam.com
Researchers and customers can report vulnerabilities to security@anubavam.com with reproduction steps. We acknowledge within two business days and we do not pursue good faith researchers who follow this process. There is no paid bug bounty programme.
Open channel
11 · Sub-processors

Sub-processors

Who else touches your data.

These are the sub-processors engaged to deliver the platform itself. Integration services are different: they only receive data if your institution enables that integration.

Sub-processor
Purpose
Engaged
Status
Oracle Cloud Infrastructure
Cloud infrastructure hosting and storage for the platform and its databases
Core platform
Always
Amazon Web Services
Cloud infrastructure and supporting services, including object storage
Core platform
Always
Amazon Simple Email Service
Transactional email delivery where the institution uses platform email
Where applicable
Conditional
Integration endpoints
Integration platforms, CRM, identity, collaboration suites, service management, learning platforms, payment gateways and the configured model provider. Each receives data only if your institution enables that integration.
Customer enabled
Named on request
The current list, with purpose and region, is provided to customers and reviewers on request from compliance@anubavam.com. Request the list →
12 · Accessibility

Accessibility

Raise accessibility early, and we will handle it openly.

Accessibility conformance is a legal procurement requirement for United States public institutions and for EU and UK bodies. We do not yet hold the audited artefact those teams need, so this section states the position plainly rather than claiming a standard we cannot evidence.

WCAG 2.1 AA auditIndependent audit
An independently audited WCAG 2.1 AA conformance assessment has not been completed. Commissioning one is on the product roadmap.
To be commissioned
VPATSection 508 procurement
A Voluntary Product Accessibility Template will be produced from that audit. Institutions with a Section 508 or EN 301 549 gate should raise it early so we can agree how it is handled during procurement.
In progress
Automated accessibility testingCI pipeline
Automated accessibility checks in the build pipeline, alongside the existing security gates, are planned so that regressions are caught with the same discipline as security findings.
In progress

Security documentation

Tell us what your review needs, and what it blocks on.

We route requests to the person who owns the answer. If an artefact does not exist, you will hear that in the first reply rather than in week three of the evaluation.

ISO/IEC 27001 certificate and scopeCurrent certificateOn request
ISO/IEC 27701 certificatePrivacy managementOn request
Data Processing AgreementProcessor terms and sub-processorsOn request
Sub-processor listPurpose and regionOn request
Security questionnaire responsesYour institution's own templateNDA · on request
Architecture and deployment overviewHosting, isolation, integrationsNDA · on request
HECVAT Full 4.0Completed, shared under NDAOn request
VPAT and WCAG auditAudit to be commissionedIn progress
SOC 2 Type 2 reportNot held. ISO evidence offeredOn request
Security testing summaryInternal testing and pipeline evidenceNDA · on request

Or write to compliance@anubavam.com. NDA available on request.

Vulnerabilitiessecurity@anubavam.com
Privacy and data subjectsdpo@anubavam.com
Questionnaires and certificatescompliance@anubavam.com
Contracts and clauseslegal@anubavam.com
14 · FAQ

Frequently asked

Plain answers for a security review.

Is Creatrix Campus SOC 2 or ISO 27001 certified?

Anubavam, the company behind Creatrix Campus, holds ISO/IEC 27001 and ISO/IEC 27701 certification. Both certificates, with their scope statements, are shared with reviewers on request.

We do not hold a SOC 2 Type 2 report. Institutions that treat SOC 2 as a hard gate should raise it at the start, and we will discuss the ISO certificate and scope, internal audit records and questionnaire responses we provide in its place.

Have you completed a HECVAT?

HECVAT Full 4.0 is completed and available on request under NDA, because it is the instrument most United States institutions require. We also complete your institution’s own questionnaire directly, section by section, and flag anything that needs discussion before you read it.

Where is our data stored, and can we choose the region?

The platform runs on Oracle Cloud Infrastructure and Amazon Web Services. The hosting region for your tenant is confirmed with the account team and recorded contractually before signature.

Residency is agreed per institution rather than assumed from a map, and an on-premises or private cloud deployment is available where national sovereignty rules require it.

What are your uptime, backup and disaster recovery commitments?

The uptime service level is 99.9%, with regional status published at status.creatrixcampus.net. Backups combine point in time recovery with daily and monthly snapshots, and continuous backup of uploaded files.

Disaster recovery backups are taken every 24 hours to a second availability zone in the same region, giving a recovery point objective of 24 hours and a recovery time objective of 24 to 48 hours.

Do you support single sign-on and multi-factor authentication?

SAML 2.0 single sign-on is supported, along with Active Directory and LDAP integration, so accounts stay governed by your identity provider.

For direct sign-in, two factor authentication uses a one time passcode sent to the registered email address. Institutions requiring authenticator apps or FIDO2 enforce them at their identity provider, which the platform honours through SAML. SCIM provisioning is on the roadmap for very large deployments, and accounts are otherwise managed through the platform and its APIs.

Do you train AI models on our institutional data?

Your data is not used to train third party models as part of the standard service, and AI features are enabled or disabled by your administrator. Institutions whose policy prohibits AI on student data can run the platform with those features off.

Alignment to ISO/IEC 42001 and NIST AI RMF, an impact assessment for AI features, and a no training clause in the standard agreement are all in progress. Reviewers who need the owner and the target date should ask.

Are your products WCAG 2.1 AA conformant, and do you have a VPAT?

Not yet. There is no independently audited WCAG 2.1 AA conformance assessment and no VPAT today. An audit is being commissioned and automated accessibility testing is being added to the build pipeline.

If a VPAT is a procurement requirement for your institution, tell us at the first meeting so it can be handled openly.

How do we report a vulnerability or a live security incident?

Report vulnerabilities to security@anubavam.com with a description, reproduction steps and your contact details. We acknowledge within two business days and we do not pursue good faith researchers who follow this process.

For a live incident affecting your institution, write to incidents@anubavam.com. Confirmed incidents affecting customer data are notified within 72 hours.

The close

Bring us your hardest security questions.

Send the questionnaire. You will get direct answers, named owners and the documents behind them.