A vendor certificate does not make your system compliant
We explain what the platform covers, what remains your responsibility, and which documents and technical evidence we provide for assessment.
CERTIFICATES AND SCOPE
Certificates: what they cover and what they do not
Certified at the vendor
ISO/IEC 27001:2022 — development and support of the no-code platform for process automation and CRM. Bureau Veritas, UK.ISMS.287, valid through 08.06.2028. The ISMS has operated since 2016. ISO 9001:2015 — software development, customization of automated systems, Creatio Cloud service, and customer support. TÜV NORD, valid through 15.04.2028. In place since 2019. This demonstrates that platform releases are produced within audited management systems.
Certified for the vendor cloud
SOC 2 Type II — an independent annual audit of Creatio Cloud controls, including DR and BCP procedures. ISO/IEC 27017 and 27018 cover cloud-service security and protection of personal data in the cloud. For on-premise deployment, your infrastructure is outside this scope.
Capabilities, not certificates
GDPR — built-in tools supporting compliance with the EU regulation. HIPAA — mechanisms for protecting medical data. WCAG 2.0–2.2 AA, Section 508, and EN 301 549 — interface accessibility capabilities.
Important
A vendor certificate does not make your system compliant. It is evidence used in assessing your system — and that assessment is conducted by the system owner, meaning you.
Who is responsible for what
| Area | Responsible party |
|---|---|
| Secure platform development lifecycle, vulnerability management, SLA-based patching, vulnerability notices | Creatio as the software vendor |
| Application module: operation roles, record permissions, production-contour event logs | Syntech Digital |
| Servers, network, operating system, database, backups, access, monitoring, incident response | Customer for on-premise |
| Security authorization, selection of protection measures, authorization letter | System owner, meaning the customer |
SUPPLY CHAIN
Supplier risk levels under State Service Order No. 836
Risk Level I
Seventeen basic cyber-hygiene measures, confirmed declaratively when the contract is signed.
Risk Levels II–IV
A basic or sector security profile, evidenced by one of three documents: security authorization, an information-security conformity certificate, or a valid KSZI attestation.
Who determines the level
The customer determines the level using its methodology and the supplier’s access to its environment. A supplier confirms measures only within what it actually controls.
DEPLOYMENT
Three models, different responsibility boundaries
On-premise in your environment
The customer administers the infrastructure and data stays in its environment. Availability, RPO, and RTO are set by the customer’s own regulations.
Private cloud
Data and administration are divided according to the agreement with your provider. Availability, backup, and recovery targets belong in your SLA.
Creatio Cloud
Creatio administers the infrastructure. Creatio Cloud metrics are SLA 99.5% — up to 99.95% for dedicated high-availability architecture, RPO ≤ 24 hours, and indicative RTO ≤ 1 hour per 100 GB.
ARTIFICIAL INTELLIGENCE
Order No. 154 contains recommendations, not an AI ban
State Service Order No. 154 of 23.02.2026 contains cybersecurity recommendations for systems using artificial intelligence. In higher-assurance environments, external AI services can be disabled in a controlled way or replaced with a local model. AI access should be designed within the user’s permissions: an agent must not see more than the person on whose behalf it operates.
LIMITS OF OUR ROLE
What we do not do
Not a technical or cryptographic protection licensee
We are not licensed to provide technical or cryptographic information-protection services.
Not an assessment entity
We do not have assessment-entity status and do not conduct authorization instead of the system owner.
Not legal advice
We do not provide legal services. A qualified electronic signature under DSTU 4145 is implemented through integration with a qualified trust-service provider; none of the major international platforms provides it natively.
Discuss your environment
We will review the deployment model, responsibility boundaries, and evidence needed for your target security profile.