Security & Standards

Control remains with the organization.

CREA-KO’s security model starts from a simple allocation: the organization owns its infrastructure, its data and its access decisions. The engineering below exists to keep it that way — not as a layer added at the end, but as a chain of control that runs from ownership through operation, review, maintenance and recovery.

The trust chain

Six layers of control. Each one carries into the next.

Trust is not one feature. Ownership decides who controls; boundaries decide where; authorization decides who may act; records make action answerable; maintenance keeps all of it true over years; and standards give the work its discipline. Break any link and the ones after it stand on nothing.

  1. Ownership

    Who controls the environment, the data and the decisions about both — allocated explicitly, first.

  2. Deployment boundaries

    Where the system operates and what it may touch — chosen per environment, then governed.

  3. Identity & authorization

    Who may act, in which role, on what — authority granted through the organization, at the smallest useful scope.

  4. Records & auditability

    Actions and decisions leave durable records, so governed action can be reconstructed and answered.

  5. Maintenance & continuity

    Updates, support, recovery planning and knowledge continuity preserve the control model over years.

  6. Standards & discipline

    Certified management systems give the work its operating discipline — they inform responsibility; they do not replace it.

The trust chain, read top to bottom. Ownership establishes who controls the environment and data; deployment defines where the system operates and where boundaries sit; identity and authorization govern who may act; actions create records that support review and accountability; maintenance and continuity preserve the control model over time; and certified standards provide operating discipline without replacing implementation responsibility. Each layer’s control carries into the next — one connected trust system, not separate security features.

The control model

Infrastructure & data

  • Client-controlled infrastructure

    Systems operate on-premises or in private environments under the organization’s ownership. Modernization does not require surrendering operational data to a public cloud.

  • Data sovereignty

    Data, configuration and institution-specific learning remain inside the organization’s controlled environment by default.

Access & accountability

  • Identity and least privilege

    Role-based access with least-privilege design: each user holds exactly the authority their role carries, no more.

  • Auditability and segregation of duties

    Every action carries identity, authorization and history. Duties that must not concentrate in one person are separated by the system itself.

Engineering & continuity

  • Secure development practices

    Engineering, review and release run under CREA-KO’s certified management systems for quality, information security and service management.

  • Resilience and recovery

    Backup, recovery and continuity planning are part of system design and are exercised with the operating institution.

  • Maintenance and security updates

    Under contract, deployed systems receive maintenance, monitoring where agreed, and security updates across their working life.

Controls are specified per system and contract. CREA-KO claims only what a specific engagement implements and verifies — security is stated as engineering, not as promise.

Standards

Certified management systems.

The frameworks CREA-KO’s engineering and delivery are certified against, alongside its data-protection compliance certificate.

ISO certifications

  • ISO 9001:2015 mark

    ISO 9001:2015

    Quality Management — certified management system

  • ISO/IEC 27001:2022 mark

    ISO/IEC 27001:2022

    Information Security Management — certified management system

  • ISO/IEC 20000-1:2018 mark

    ISO/IEC 20000-1:2018

    IT Service Management — certified management system

Regulation compliance

  • GDPR Compliance mark

    GDPR Compliance

    Data Protection — Certificate of Compliance

Security review

For evaluators and reviewers.

Procurement and security teams can request system-specific documentation — deployment models, access design, audit capability and continuity planning — through a direct conversation. Security concerns about CREA-KO systems can be reported to info@crea-ko.com.

Put your deployment requirements on the table.

On-premises, private environment, integration constraints, audit demands — the conversation starts from your controls.