Where does my IP live? Is it used to train models?
Your IP stays yours. Creopus does not use customer data to train any model, and does not sell or share it.
Where your data lives
- At rest: MongoDB Atlas in the Mumbai (
ap-south-1) region, and Cloudflare R2 for file attachments. Encryption at rest with KMS-managed keys; TLS in transit. - LLM processing: prompts are sent to the provider chain — Google Vertex AI (
asia-south1), Cerebras, and Anthropic. Vertex processes in-region (Mumbai); Cerebras and Anthropic process in the United States. A prompt only reaches a fallback provider if the one before it is unavailable or the content exceeds its context window. - In-region mode: the platform supports a deployment mode that removes US-processing providers from the chain entirely and fails closed — if no in-region provider can serve the request, it refuses rather than silently sending data abroad. This is a deployment-level setting today, not a per-customer toggle. Talk to us if you need it.
What we do not retain
We do not retain your prompts or outputs for model training, and no provider in the chain trains on data submitted through a paid API tier under their standard terms.
We have not yet completed zero-data-retention (ZDR) enrolment with our providers. Until we have, provider-side retention follows each provider's standard API terms rather than a negotiated ZDR agreement. If ZDR is a requirement for your programme, raise it with us before you upload controlled data — we would rather tell you this now than have you discover it in a security review.
Access and audit
- Access is role-based, resolved per hierarchy node with inherited team roles (owner / editor / viewer) and separate reviewer access.
- Security and authentication events are recorded server-side. A customer-facing audit trail — one you can query and export yourself — is in development. Today, retrieving audit records for your workspace requires asking us.
- Review sign-off uses tamper-evident electronic signatures with step-up re-authentication at the point of signing.
Certifications
We are not SOC 2 or ISO 27001 certified, and no audit is currently underway. Both are on the roadmap; we are not going to give you a date we cannot stand behind.
What exists today is our internal security documentation — written to answer the questions a SOC 2 report would, with every claim tagged as verifiable in code, in infrastructure, or by policy. Most security reviews we have been through are satisfied by it plus a signed NDA and DPA. If your procurement process has a hard certification gate, tell us early so neither side wastes time.
Deleting your data
Account deletion purges your artifacts, attachments and derived records across the platform. Records under an active controlled-document retention latch (baselines, signed reviews, requirement history) are retained as the compliance workflow requires, rather than being silently destroyed.