Security & Standards
Control remains with the organization.
CREA-KO’s security model starts from a simple allocation: the organization owns its infrastructure, its data and its access decisions. The engineering below exists to keep it that way — not as a layer added at the end, but as a chain of control that runs from ownership through operation, review, maintenance and recovery.
The trust chain
Six layers of control. Each one carries into the next.
Trust is not one feature. Ownership decides who controls; boundaries decide where; authorization decides who may act; records make action answerable; maintenance keeps all of it true over years; and standards give the work its discipline. Break any link and the ones after it stand on nothing.
Ownership
Who controls the environment, the data and the decisions about both — allocated explicitly, first.
Deployment boundaries
Where the system operates and what it may touch — chosen per environment, then governed.
Identity & authorization
Who may act, in which role, on what — authority granted through the organization, at the smallest useful scope.
Records & auditability
Actions and decisions leave durable records, so governed action can be reconstructed and answered.
Maintenance & continuity
Updates, support, recovery planning and knowledge continuity preserve the control model over years.
Standards & discipline
Certified management systems give the work its operating discipline — they inform responsibility; they do not replace it.
Four trust territories
Where the chain is examined in depth.
- Data Sovereignty Who controls the data, infrastructure, access and knowledge?
- Controlled Deployment How does a system enter a real environment without weakening it?
- Access & Auditability How does identity become authorized, answerable action?
- Business Continuity What keeps critical operation available through change and disruption?
The control model
Infrastructure & data
Client-controlled infrastructure
Systems operate on-premises or in private environments under the organization’s ownership. Modernization does not require surrendering operational data to a public cloud.
Data sovereignty
Data, configuration and institution-specific learning remain inside the organization’s controlled environment by default.
Access & accountability
Identity and least privilege
Role-based access with least-privilege design: each user holds exactly the authority their role carries, no more.
Auditability and segregation of duties
Every action carries identity, authorization and history. Duties that must not concentrate in one person are separated by the system itself.
Engineering & continuity
Secure development practices
Engineering, review and release run under CREA-KO’s certified management systems for quality, information security and service management.
Resilience and recovery
Backup, recovery and continuity planning are part of system design and are exercised with the operating institution.
Maintenance and security updates
Under contract, deployed systems receive maintenance, monitoring where agreed, and security updates across their working life.
Controls are specified per system and contract. CREA-KO claims only what a specific engagement implements and verifies — security is stated as engineering, not as promise.
Standards
Certified management systems.
The frameworks CREA-KO’s engineering and delivery are certified against, alongside its data-protection compliance certificate.
ISO certifications

ISO 9001:2015
Quality Management — certified management system

ISO/IEC 27001:2022
Information Security Management — certified management system

ISO/IEC 20000-1:2018
IT Service Management — certified management system
Regulation compliance

GDPR Compliance
Data Protection — Certificate of Compliance
Security review
For evaluators and reviewers.
Procurement and security teams can request system-specific documentation — deployment models, access design, audit capability and continuity planning — through a direct conversation. Security concerns about CREA-KO systems can be reported to info@crea-ko.com.
Put your deployment requirements on the table.
On-premises, private environment, integration constraints, audit demands — the conversation starts from your controls.