1. Our approach
Creodome is a small, focused studio. That means fewer people touching production, fewer moving parts, and a security posture we can actually describe honestly. This page tells you exactly what we do today and where we're heading.
2. Infrastructure (current marketing site)
- Hosting: Vercel (edge network) for creodome.com.
- Object storage / customer databases: Not yet used for marketplace uploads or ledger data. When the marketplace launches, this section will name storage and database providers for creator uploads, originality records, and ledger data.
- Content delivery: Vercel Edge.
- Region: primarily United States (Vercel global CDN for delivery).
3. Encryption
- In transit: TLS for all connections to creodome.com (certificates managed by the hosting platform).
- At rest: When product databases and object storage are introduced, customer data will be encrypted at rest (AES-256 or equivalent platform default).
- Passwords: When accounts launch, passwords will be hashed with bcrypt (or stronger). We never store plaintext passwords.
4. Access controls
- Production access is limited to authorized personnel only.
- Infrastructure logins require multi-factor authentication where the provider supports it.
- Third-party provider access uses least-privilege API keys scoped to the minimum required permissions.
5. AI subprocessors and customer data
Product AI providers are not yet processing customer content. When they are, none will be permitted to train their models on Creodome customer data where we can enforce that contractually or via API mode. See Privacy Policy §4 for the live marketing-site list and the commitment to disclose product providers before launch.
6. Backups & recovery
The marketing site is statically deployed via Vercel; recovery is redeploy from source control. When product databases launch, we will publish concrete backup retention, RTO, and RPO targets on this page.
7. Uptime & status
We target high availability for creodome.com via Vercel. A dedicated status page will be linked here when available.
8. Product security
- We follow OWASP guidance for common web vulnerabilities.
- Dependencies are monitored for known CVEs and patched promptly for critical issues.
- We rate-limit login and API endpoints to mitigate abuse once those endpoints exist.
9. Responsible disclosure
If you discover a security issue, please email hello@creodome.com with enough detail for us to reproduce it. We commit to:
- Acknowledging your report within 2 business days.
- Providing a status update within 10 business days.
- Not pursuing legal action against good-faith researchers who follow this policy.
A machine-readable disclosure policy is published at /.well-known/security.txt.
10. Incident response
In the event of a confirmed incident affecting customer data, we will notify affected users by email within 72 hours of confirmation, notify applicable regulators within statutory deadlines, and publish an incident summary when a status page exists.
11. What we don't have yet (transparently)
We are pre-launch and small. As of the last-updated date above:
- We do not yet have a SOC 2 report. A SOC 2 Type I readiness assessment is planned for a later phase.
- We do not yet have an ISO 27001 certification.
- We do not offer SSO/SAML, SCIM provisioning, or customer-managed encryption keys today. These are on the roadmap for a future Teams/Business tier.
Questions? hello@creodome.com.
