Creately Security & Support Schedule
Security controls, service availability and support targets
| Provider | Cinergix Pty Ltd (ABN 69 130 459 906), trading as Creately |
| Version | 1st July 2026 |
| Registered office | Unit 1, 20 Collins Street, Mentone, Victoria 3194, Australia |
Operational confirmation required The public Creately security posture supports the controls below, but the bracketed contacts and any SLA, RTO, RPO or support targets should be confirmed with Security, Engineering and Customer Success before publication.
1. Security program and assurance
1.1 Creately will maintain a documented information security program appropriate to the nature of the Service and Customer Data, including governance, risk management, policies, workforce security, access control, secure development, vendor management, incident response, business continuity and periodic review.
1.2 Creately maintains ISO/IEC 27001 certification and a SOC 2 Type II report for the scope stated in the applicable certificate and report. Current assurance materials are available to eligible enterprise customers under confidentiality restrictions.
1.3 Creately may update certifications or controls where the replacement provides materially equivalent or better protection.
2. Hosting and data residency
2.1 The Service is hosted using Amazon Web Services or another enterprise cloud provider identified in Creately’s security materials.
2.2 Available regional hosting options include Australia, the European Union and the United States, subject to product availability. The Customer’s selected primary hosting region is stated in the Order Form.
2.3 Customer Data may be accessed from another location only as needed for authorised support, security, resilience or Subprocessor operations and in accordance with the DPA.
3. Technical and organisational controls
| Control area | Commitment |
|---|---|
| Encryption | TLS 1.2 or higher for data transmitted over public networks; AES-256 or equivalent industry-standard encryption for Customer Data at rest, including backups where supported by the hosting architecture. |
| Identity and access | Unique workforce identities, least-privilege access, MFA for privileged or production access, periodic access review, and prompt revocation on role change or termination. |
| Customer controls | Role-based access control, SSO and other administrative controls according to subscribed features and product configuration. |
| Logging and monitoring | Logging of material administrative and security events, central monitoring and alerting for production systems, and retention appropriate to security and compliance needs. |
| Network security | Segmentation, firewalls/security groups, restricted administrative access, secure remote access, and monitoring for suspicious activity. |
| Vulnerability management | Regular vulnerability scanning, risk-based remediation, patch management and independent penetration testing at least annually for relevant production scope. |
| Secure development | Code review, change control, separation of environments, dependency and secret management, and security consideration through the development lifecycle. |
| Personnel | Confidentiality obligations, security awareness, role-appropriate training and background screening where lawful and appropriate. |
| Vendor management | Risk-based review of material Subprocessors and contractual security and confidentiality requirements. |
| Data handling | Logical tenant separation, restricted support access, controlled exports, and secure disposal or deletion in accordance with the DPA. |
4. Incident response
4.1 Creately will maintain an incident response process covering preparation, detection, triage, containment, investigation, remediation, recovery and post-incident review.
4.2 Customer notification for a Personal Data Breach is governed by the DPA. Operational security notices may be provided through the Customer’s designated contacts.
5. Backups and business continuity
5.1 Creately will maintain production redundancy and backup processes appropriate to the Service. Core production datastores are backed up at least every 24 hours unless a more frequent schedule applies.
5.2 Creately will periodically test restoration and disaster-recovery procedures.
5.3 Unless the Order Form states different targets, the service recovery objectives for core Atlas production data are: recovery point objective (RPO) of 24 hours and recovery time objective (RTO) of 24 hours. These targets are objectives, not guarantees, and exclude Customer-controlled systems and third-party services.
6. Availability commitment
6.1 If the Order Form includes the Enterprise Availability SLA, Creately will use commercially reasonable efforts to make the production Service available at least 99.5% of each calendar month.
6.2 Availability is calculated as: (total minutes in month minus Unavailable Minutes) divided by total minutes in month, multiplied by 100.
6.3 Unavailable Minutes exclude: scheduled maintenance notified at least five business days in advance; emergency maintenance; Customer systems, configurations, data or acts; third-party products outside Creately’s control; internet or telecommunications failures outside Creately’s control; force majeure; suspension permitted by the Agreement; beta features; and use contrary to Documentation.
6.4 The Customer must request a service credit within 30 days after the affected month and provide reasonable details. Credits are calculated against the monthly equivalent of the affected subscription fee.
| Monthly availability | Service credit |
|---|---|
| Below 99.5% but at least 99.0% | 5% |
| Below 99.0% but at least 98.0% | 10% |
| Below 98.0% | 15% |
6.5 Service credits are the Customer’s sole monetary remedy for failure to meet the availability commitment, are capped at 15% of the monthly equivalent fee, and may be applied only to future invoices. No credit applies unless the Order Form includes the Enterprise Availability SLA.
7. Maintenance
7.1 Creately will use reasonable efforts to schedule planned maintenance outside the Customer’s primary business hours and provide at least five business days’ notice for maintenance expected to materially affect availability.
7.2 Emergency maintenance may occur with shorter notice where reasonably necessary to protect security, integrity or continuity.
8. Support
8.1 Support channels: [support portal], support@creately.com and any dedicated channel stated in the Order Form.
8.2 Standard Support Hours are 9:00 am to 5:00 pm Melbourne time on Victorian business days. An Order Form may include expanded or 24x7 P1 support.
| Priority | Description | Target initial response |
|---|---|---|
| P1 – Critical | Production Service is unavailable for most users, or a confirmed severe security issue, with no reasonable workaround. | 4 business hours; 24x7 only if purchased |
| P2 – High | Material production functionality is unavailable or seriously degraded for multiple users; workaround is limited. | 1 business day |
| P3 – Normal | Non-critical defect or degraded function with a reasonable workaround. | 2 business days |
| P4 – Low / Request | How-to question, minor issue, documentation request or enhancement request. | 3 business days |
8.3 Response targets are targets for acknowledgement and commencement of investigation, not resolution commitments. Resolution depends on severity, reproducibility, third-party dependencies and Customer cooperation.
8.4 The Customer must provide reasonable diagnostic information, maintain supported browsers and configurations, and cooperate with troubleshooting.
9. Security reviews and evidence
9.1 On request and subject to confidentiality, Creately will provide its current ISO certificate, SOC 2 report or bridge letter where available, security overview and reasonable responses to a standard security questionnaire.
9.2 Customer testing must be authorised in writing. The Customer must not conduct denial-of-service testing, social engineering, destructive testing or testing that accesses another customer’s data.
10. Changes
10.1 Creately may update this Schedule to reflect control improvements, legal changes or service evolution. The version identified in an Order Form remains applicable for the current Subscription Term unless the update provides materially equivalent or better protection or the parties agree otherwise.