Book a demo
Two people in a warm conversation at a wooden table, coffee mugs between them
Security & trust

Built to pass procurement, not just product review

Security and trust are often the first real blocker for regulated buyers evaluating Creatium or the APIs, so here’s where we stand today.

Our commitment

We do not use any input, output, or personal information to train third-party service provider AI technology.

Security & trust

Where we stand

Data privacy

We don’t use your inputs, outputs, or personal information to train third-party AI providers. Creatium is built to comply with GDPR and UK GDPR, along with privacy laws in Canada, Australia, New Zealand, South Africa, and 20 US states.

Security practices

We disclose every AI subprocessor we rely on (including Anthropic, OpenAI, ElevenLabs, Cartesia, Perplexity, and AWS and Azure AI) and apply human review to AI-generated content in our services work.

Compliance

We align to GDPR, UK GDPR, and FERPA. We only list certifications we can produce evidence for. See the certifications below, and ask us anytime.

Accessibility

We conform to WCAG 2.1 AA and Section 508, with captions, screen-reader support, and respect for system preferences like reduced motion. A VPAT is available on request.

LMS integration

Coach content is SCORM-compliant and distributes through your LMS with progress tracking, centralized content management, and learning-path delivery.

Certifications & conformance

What we can produce evidence for today. Ask and we’ll share the report, DPA, or VPAT.

GDPR & UK GDPR

Built to comply, with a Data Processing Addendum available for customers.

FERPA

Supports FERPA obligations for customers handling student education records.

WCAG 2.1 AA + Section 508

Conformant, with captions and screen-reader support. A VPAT is available on request.

SSO / SAML

Enterprise single sign-on through your SAML identity provider.

How we handle AI and your data

01

We never use your inputs, outputs, or personal information to train third-party AI.

02

Every AI subprocessor we use is disclosed in our privacy notice.

03

AI-generated content in our services work is reviewed by a human.

04

Avatars are used only with consent from the individuals or their estates, with consultation for Indigenous communities.

A person at a laptop in a quiet room, warm light falling from one side

What we commit to contractually

Encryption in transit and at rest

Access controls, encryption in transit and at rest, logical segregation, vulnerability management, and logging and monitoring.

Breach notification

We’ll notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own compliance obligations.

Deletion and backup retention

We delete your content within 60 days of termination, plus standard backup retention of up to 90 additional days, after which backups are overwritten.

Subprocessor change notice

At least 30 days' notice before we add a new subprocessor, with the right to object on reasonable grounds.

Audit rights

On reasonable notice, we’ll provide the information needed to demonstrate compliance, and permit an on-site audit once every 12 months.

Subprocessors

Anthropic

AI

OpenAI

AI

ElevenLabs

AI

Cartesia

AI

Perplexity

AI

Amazon Web Services (AWS) AI

AI

Microsoft Azure AI

AI

Google Analytics

Analytics

A woman alone at a desk with her laptop, chin resting on her hand, looking out at forested hills