🔒 Security at CreonOS

Last Updated: February 4, 2026
Security is Our Priority. CreonOS handles sensitive code and proprietary projects. We implement enterprise-grade security measures to protect your data and maintain platform integrity.
✅ TLS 1.3 Encryption ✅ SOC 2 Hosting ✅ Bcrypt Passwords ✅ Rate Limiting ✅ CSRF Protection ✅ Regular Audits

1. Infrastructure Security

1.1 Hosting & Compliance

1.2 Encryption

1.3 Database Security

2. Application Security

2.1 Authentication & Authorization

2.2 API Security

2.3 WebSocket Security

3. Code Execution Security

3.1 AI Agent Sandboxing

3.2 Code Validation

4. Data Protection

4.1 User Data Isolation

4.2 AI Provider Data Handling

When sending code to AI providers (Claude, GPT-4, Gemini, DeepSeek):

4.3 Data Retention

5. Monitoring & Incident Response

5.1 Security Monitoring

5.2 Incident Response Plan

In the event of a security incident:

  1. Detection: Automated alerts notify security team within minutes
  2. Containment: Isolate affected systems to prevent spread
  3. Investigation: Forensic analysis to determine scope and cause
  4. Remediation: Patch vulnerabilities and restore service
  5. Notification: Inform affected users within 72 hours (GDPR requirement)
  6. Post-Mortem: Document lessons learned and improve defenses

5.3 Breach Notification

If your data is compromised, we will:

6. Vulnerability Disclosure Program

🐛 Found a Security Issue? We Want to Hear From You.

CreonOS welcomes responsible disclosure of security vulnerabilities. If you discover a security issue, please report it privately rather than publicly disclosing it.

How to Report

Email: security@creonai.co.uk

PGP Key: Available at /pgp-key.txt (for encrypted reports)

What to Include

Our Commitment

Bug Bounty (Coming Soon)

We're planning a bug bounty program for 2026. High-severity vulnerabilities may be eligible for rewards up to $5,000.

7. Security Best Practices for Users

7.1 Protect Your Account

7.2 Secure Your Code

7.3 Recognize Phishing

CreonOS will NEVER:

If you receive a suspicious email claiming to be from CreonOS, forward it to security@creonai.co.uk.

8. Compliance & Certifications

8.1 Current Compliance

8.2 In Progress (2026)

9. Third-Party Security

9.1 Vetted Integrations

CreonOS only integrates with security-conscious providers:

9.2 Regular Audits

We conduct quarterly reviews of third-party security practices and update integrations as needed.

10. Security Updates

10.1 Platform Updates

10.2 Transparency

Major security updates are announced via:

11. Contact Security Team

For security concerns, questions, or reports:

Email: security@creonai.co.uk Support: support@creonai.co.uk Emergency: security-emergency@creonai.co.uk (critical issues only) PGP Key: https://creonai-backend-production-0dbc.up.railway.app/pgp-key.txt

Response Times:

Security Summary: CreonOS uses enterprise-grade security (TLS 1.3, AES-256, bcrypt, rate limiting, SOC 2 hosting). Your code is isolated, encrypted, and never used for AI training without consent. Found a vulnerability? Email security@creonai.co.uk.