At Creative Force, safeguarding the security, confidentiality and availability of your data is fundamental to everything we do. We hold ourselves to internationally recognised frameworks and industry standards, and put our practices to the test through independent third-party assessments and regular security testing.
Safeguarding student data in regulated environments
Creative Force has achieved approval under Australia’s ST4S government assurance framework for use within state education systems. The framework evaluates vendors against defined requirements for security, privacy and governance in regulated school environments. While geographically specific, this approval reflects our ability to operate as secure infrastructure supporting organisations managing student data and other sensitive information.
Published on Feb 24, 2026

Documentation of our compliance against global standards including certifications, attestations, and audit reports.

GDPR
SOC2
ISO27001
PCI DSS
Microsoft SSPA
Cyber Essentials
Diagram
Data flow
Statement of applicability
ISO 27001
Report
Penetration test 2026
Report
2025 SOC2 Type I
Procedure
Information requests
Certificate
Insurance 2025-2026
Certificate
Cyber Essentials 2025
Report
2025 SOC2 Type II
Network diagram
All regions
Report
SSPA 2026
Vulnerability scan
H1 2026
Report
PCI-DSS SAQ-D 2025
Certificate
ISO 27001 (2022 standard)
Incident management
Data classification
Risk management
Capacity management
Acceptable use
Backup policy
Information security
Access control
Vendor management
Change management
Personnel code of conduct
Business continuity & disaster recovery plan
Vulnerability management
Asset management

Creative Force encrypts all data at rest (AES-256bit) and in transit (minimum TLS 1.3) using secure ciphers.

Client data is stored within Creative Force’s approved Cloud Service Provider: Amazon Web Services. Data resides in a client approved region.
We offer a choice of data residency in the following regions: Australia, Canada, European Union, Hong Kong, United Arab Emirates, United States.

Creative Force maintains a list of authorised sub-processors whose appropriate technical and organisation measures have been established and maintained. Please see: https://creativeforce.team/privacy-policy/ and https://creativeforce.team/sub-processors/ for more information.

All Creative Force personnel receive security and privacy awareness training both during onboarding and throughout the year thereafter. Such training covers topics such as good password management, information security, phishing awareness, and compliance topics with regards to privacy and data protection.
A full database backup is taken every 24 hours. Database snapshots are taken every 5 minutes. All database backups and snapshots are retained for 30 days. Our current recovery time is around 90 mins from the latest available snapshot, but Our goals for 2026 is to maintain and average RTO (Recovery Time Objective) under 1.5 hours.
We are committed to providing you with the best possible experience, which includes the security, privacy and integrity of your personal data. For more details, see the links below.

Security

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Certificates, reports and audits*

Policies
*
If you need assistance, please contact support