Security Overview
Effective June 18, 2026 · Last updated June 18, 2026
This Security Overview describes the administrative, technical, and physical safeguards that The Cur8 Group Corp. ("CreateBase") uses to protect Customer Data processed through the CreateBase Platform. It is provided for informational purposes and is incorporated by reference into the Master Subscription Agreement. Certain items below are identified as roadmap or in-progress and reflect CreateBase's current plans rather than completed certifications. CreateBase may update its security practices over time, provided that it will not materially reduce the overall security of the Services during a paid subscription term.
1. Security Governance
CreateBase maintains an information security program with documented policies and assigned ownership for security decisions. The program is reviewed periodically and updated to reflect changes in CreateBase's operations, applicable law, and the threat landscape. Risk assessments inform prioritization of security controls and remediation.
2. Encryption in Transit and at Rest
Data transmitted between Customer and the Platform is encrypted in transit using current versions of Transport Layer Security (TLS). Customer Data is encrypted at rest using industry-standard algorithms. Encryption keys are managed through the key-management facilities of CreateBase's cloud infrastructure providers with restricted access.
3. Access Control & MFA / Least Privilege
Access to systems that process Customer Data is restricted to authorized personnel based on the principle of least privilege and a need-to-know basis. Multi-factor authentication (MFA) is required for administrative access to production systems and key internal tools. Access rights are reviewed periodically and revoked promptly upon role change or termination.
4. Secure SDLC & Code Review
CreateBase follows secure software development practices, including peer code review of changes prior to deployment, separation of development and production environments, and use of version control and automated build pipelines. Security considerations are incorporated into design and development activities.
5. Vulnerability Management & Penetration Testing
CreateBase performs vulnerability scanning of its infrastructure and dependencies and remediates identified vulnerabilities on a risk-prioritized basis. CreateBase conducts periodic penetration testing of the Platform, and is expanding the cadence and scope of third-party penetration testing as part of its security roadmap.
6. Logging & Monitoring
CreateBase logs relevant system and security events and monitors production environments for anomalous activity. Logs are retained for a period appropriate to support investigation and operational needs and are protected against unauthorized access and tampering.
7. SOC 2 (In Progress)
CreateBase is working toward a SOC 2 examination of its security controls. This effort is in progress and a SOC 2 report is not yet available. CreateBase will make information regarding the status of this effort available to enterprise customers upon request and under confidentiality.
8. Subprocessor Risk Management
CreateBase engages Subprocessors to provide elements of the Services and evaluates their security practices before engagement and on an ongoing basis. Subprocessors are bound by contractual obligations no less protective than those applicable to CreateBase under the DPA. A current list of Subprocessors is maintained at Subprocessors.
9. Incident Response & Breach Notification
CreateBase maintains an incident response process to identify, investigate, contain, and remediate security incidents. In the event of a confirmed security incident affecting Customer Data, CreateBase will notify the affected Customer without undue delay and, where required by applicable law or the DPA, within seventy-two (72) hours of becoming aware of the incident, and will provide information regarding the nature of the incident and the measures taken to address it as such information becomes available.
10. Business Continuity & Disaster Recovery
CreateBase maintains business continuity and disaster recovery measures, including regular backups of Customer Data and use of resilient cloud infrastructure across availability zones. CreateBase periodically reviews its recovery procedures and is continuing to formalize and test its business continuity and disaster recovery plans.
11. Data Segregation
The Platform is a multi-tenant environment in which Customer Data is logically segregated so that each Customer's data is isolated from that of other Customers. Access controls and application-level safeguards are designed to prevent one Customer from accessing another Customer's data.
12. Personnel Security & Training
CreateBase personnel are subject to confidentiality obligations and, where permitted by law, background screening appropriate to their role. Personnel receive security awareness training and are required to comply with CreateBase's security policies.
13. Customer Responsibilities
Security is a shared responsibility. Customer is responsible for safeguarding its account credentials, configuring and managing access for its Authorized Users, promptly removing access for users who no longer require it, enabling available security features, and promptly notifying CreateBase of any suspected unauthorized access to its account. Customer is responsible for the lawfulness of the Customer Data it submits to the Platform.
14. Contact
Questions about this Security Overview, or requests for additional security documentation, may be directed to The Cur8 Group Corp., 13223 Black Mountain Rd, Ste 1189, San Diego, CA 92129, or by email to legal@createbase.com.