Skip to content

    A vendor certificate does not make your system compliant

    We explain what the platform covers, what remains your responsibility, and which documents and technical evidence we provide for assessment.

    CERTIFICATES AND SCOPE

    Certificates: what they cover and what they do not

    Certified at the vendor

    ISO/IEC 27001:2022 — development and support of the no-code platform for process automation and CRM. Bureau Veritas, UK.ISMS.287, valid through 08.06.2028. The ISMS has operated since 2016. ISO 9001:2015 — software development, customization of automated systems, Creatio Cloud service, and customer support. TÜV NORD, valid through 15.04.2028. In place since 2019. This demonstrates that platform releases are produced within audited management systems.

    Certified for the vendor cloud

    SOC 2 Type II — an independent annual audit of Creatio Cloud controls, including DR and BCP procedures. ISO/IEC 27017 and 27018 cover cloud-service security and protection of personal data in the cloud. For on-premise deployment, your infrastructure is outside this scope.

    Capabilities, not certificates

    GDPR — built-in tools supporting compliance with the EU regulation. HIPAA — mechanisms for protecting medical data. WCAG 2.0–2.2 AA, Section 508, and EN 301 549 — interface accessibility capabilities.

    Important

    A vendor certificate does not make your system compliant. It is evidence used in assessing your system — and that assessment is conducted by the system owner, meaning you.

    Who is responsible for what

    AreaResponsible party
    Secure platform development lifecycle, vulnerability management, SLA-based patching, vulnerability noticesCreatio as the software vendor
    Application module: operation roles, record permissions, production-contour event logsSyntech Digital
    Servers, network, operating system, database, backups, access, monitoring, incident responseCustomer for on-premise
    Security authorization, selection of protection measures, authorization letterSystem owner, meaning the customer

    SUPPLY CHAIN

    Supplier risk levels under State Service Order No. 836

    Risk Level I

    Seventeen basic cyber-hygiene measures, confirmed declaratively when the contract is signed.

    Risk Levels II–IV

    A basic or sector security profile, evidenced by one of three documents: security authorization, an information-security conformity certificate, or a valid KSZI attestation.

    Who determines the level

    The customer determines the level using its methodology and the supplier’s access to its environment. A supplier confirms measures only within what it actually controls.

    DEPLOYMENT

    Three models, different responsibility boundaries

    On-premise in your environment

    The customer administers the infrastructure and data stays in its environment. Availability, RPO, and RTO are set by the customer’s own regulations.

    Private cloud

    Data and administration are divided according to the agreement with your provider. Availability, backup, and recovery targets belong in your SLA.

    Creatio Cloud

    Creatio administers the infrastructure. Creatio Cloud metrics are SLA 99.5% — up to 99.95% for dedicated high-availability architecture, RPO ≤ 24 hours, and indicative RTO ≤ 1 hour per 100 GB.

    ARTIFICIAL INTELLIGENCE

    Order No. 154 contains recommendations, not an AI ban

    State Service Order No. 154 of 23.02.2026 contains cybersecurity recommendations for systems using artificial intelligence. In higher-assurance environments, external AI services can be disabled in a controlled way or replaced with a local model. AI access should be designed within the user’s permissions: an agent must not see more than the person on whose behalf it operates.

    LIMITS OF OUR ROLE

    What we do not do

    Not a technical or cryptographic protection licensee

    We are not licensed to provide technical or cryptographic information-protection services.

    Not an assessment entity

    We do not have assessment-entity status and do not conduct authorization instead of the system owner.

    Not legal advice

    We do not provide legal services. A qualified electronic signature under DSTU 4145 is implemented through integration with a qualified trust-service provider; none of the major international platforms provides it natively.

    Discuss your environment

    We will review the deployment model, responsibility boundaries, and evidence needed for your target security profile.

    Discuss the environment