At Creative Force, safeguarding the security, confidentiality and availability of your data is fundamental to everything we do. We hold ourselves to internationally recognised frameworks and industry standards, and put our practices to the test through independent third-party assessments and regular security testing.
SOC 2 Type II renewal
We have renewed our SOC 2 Type II attestation, reaffirming the ongoing effectiveness of the controls we maintain to protect customer data and operate our systems securely. The assessment examines how these controls perform over time across areas including security, availability and confidentiality. This renewal reflects our continued commitment to maintaining the processes, governance and infrastructure required to support organisations handling sensitive and business-critical information.
Published on Sept 03, 2026

Documentation of our compliance against global standards including certifications, attestations, and audit reports.

GDPR
SOC2
ISO27001
PCI DSS
Microsoft SSPA
Cyber Essentials 2026
Diagram
Data flow
Statement of applicability
ISO 27001
Report
Penetration test 2026
Report
SOC2 Type I
Procedure
Information requests
Certificate
Insurance 2026-2027
Certificate
Cyber Essentials 2026
Report
2026 SOC2 Type II
Network diagram
All regions
Report
SSPA 2026
Vulnerability scan
H1 2026
Report
PCI-DSS SAQ-D 2025
Certificate
ISO 27001 (2022 standard)
Incident management
Data classification
Risk management
Capacity management
Acceptable use
Backup policy
Information security
Access control
Vendor management
Change management
Personnel code of conduct
Business continuity & disaster recovery plan
Vulnerability management
Asset management

Creative Force encrypts all data at rest (AES-256bit) and in transit (minimum TLS 1.3) using secure ciphers.

Client data is stored within Creative Force’s approved Cloud Service Provider: Amazon Web Services. Data resides in a client approved region.
We offer a choice of data residency in the following regions: Australia, Canada, European Union, Hong Kong, United Arab Emirates, United States.

Creative Force maintains a list of authorised sub-processors whose appropriate technical and organisation measures have been established and maintained. Please see: https://creativeforce.team/privacy-policy/ and https://creativeforce.team/sub-processors/ for more information.

All Creative Force personnel receive security and privacy awareness training both during onboarding and throughout the year thereafter. Such training covers topics such as good password management, information security, phishing awareness, and compliance topics with regards to privacy and data protection.
A full database backup is taken every 24 hours. Database snapshots are taken every 5 minutes. All database backups and snapshots are retained for 30 days. Our current recovery time is around 90 mins from the latest available snapshot, but Our goals for 2026 is to maintain and average RTO (Recovery Time Objective) under 1.5 hours.
We are committed to providing you with the best possible experience, which includes the security, privacy and integrity of your personal data. For more details, see the links below.

Security

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Certificates, reports and audits*

Policies
*
If you need assistance, please contact support