Security

How read-only is enforced

ctx10 reads how your Creatio is set up and never the records inside it. Everything on this page is enforced in code, and where each lock lives is written next to it.

We can tell you who changed a setting, without ever reading a customer record.

That works because ctx10 reads Creatio’s own list of users, which is a configuration table, and leaves the contact and credential columns out of the query.

Enforcement

Four locks, not one

There are four, at different points on the way to your data. Whichever route a query takes, the saved index or your live instance, it passes through at least two of them, and any one on its own would stop a write.

  1. 01

    In your Creatio: a read-only guard

    The ctx10 add-on takes one kind of command: a read. It turns down everything else before it ever reaches the database.

  2. 02

    In your Creatio: a read-only session, rolled back

    The add-on opens a session the database itself holds to read-only, and rolls it back when the read is done, even when it succeeded. A write that somehow got that far would have nothing to commit to.

  3. 03

    In our system: every query is checked before it runs

    One statement, and it has to begin with SELECT, or a WITH that leads into one. More than thirty words that write, change or reach outside the database are refused wherever they appear. This check runs on both routes, the saved index and the live instance.

  4. 04

    At the database: a read-only login

    The saved index is read under a login that cannot write, and cannot reach anything outside that data. In production, the service will not even start without it.

Data we never hold

Data we never take

No business records

We never take your business records. Contacts, accounts, leads and orders stay where they are.

Personal data we never ask for

We read configuration tables, and Creatio’s own user list is one of them. Its email, phone and password columns are left out of the capture query itself, so those values never leave your Creatio. You can ask us to switch that exclusion off.

Scoped to your workspace

The index we build for you is a database of its own. The captured rows behind it sit in one shared store, split by workspace, and every query is rewritten to your rows before it runs, or refused.

The unit is the workspace, which matters if you are an implementation partner. A partner workspace deliberately spans several of your clients, so everyone you seat in it can see all of them. A partner workspace is licensed for your own team for that reason, and your clients’ own people get a workspace of their own.

No AI training

We never train AI models on your data.

The add-on

The add-on, up close

The ctx10 add-on runs inside your Creatio, so it is the part worth looking at closely. Locks 01 and 02 again, in more detail.

A guard checks first

Every command has to be a read, one at a time. Anything else is turned down before it runs.

A read-only session, rolled back

The session is opened read-only and rolled back when it is done, so even a write that somehow got through would not stick.

Access & audit

Live access, and the log of it

Live access starts off

Reading a saved index is the normal way. To query your live instance, you turn it on for your workspace first.

We log every query

A data query is written down in full: the command we got, the command we ran, how many rows, how many bytes, the caller’s address and browser, refusals included. Tool calls, Ask and checks keep a thinner record of who, which tool, when, and how it went, never the sentence you typed. Both are kept 12 months.

Sign-in

You sign in with a password today. Single sign-on is built and stays switched off until we turn it on. Admins keep a password login as a backup either way.

Keys you control

Every key belongs to one seat and can be turned off at any time. What it can do is fixed when it is made.

Residency & sub-processors

Where your data lives

Three countries, in order. Two of them have no EU adequacy decision, which is why what follows is a set of clauses rather than a reassurance.

Germany
Servers and databases (Contabo).
Türkiye
The controller, EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ.
Tunisia
Operational access — engineering and support.

Transferred under clauses

Personal data leaving the EU or the UK moves under the standard contractual clauses (Module Two) and, for UK data, the International Data Transfer Addendum. Both are written into the Data Processing Agreement, which applies to every workspace and is published rather than offered on request.

6 companies, named

Contabo, OpenAI, IT CAPACITIES, Netlify, Microsoft 365, Google — and 3 more listed while still switched off, so the list does not have to change quietly later. What each one can actually reach is written against its name on Data & privacy.

The AI provider is off by default

AI mode is the only part of the product that calls an AI provider, and a workspace has to switch it on. The index, the checks, the exact answers and everything over MCP never call one at all — an agent asking what breaks if you rename a field is reading your index, not a model.

Nothing dials in

Every call we make to your Creatio is outbound HTTPS from our platform. There is no inbound rule to open and no callback. What that means for an allowlisted, on-premises or VPN-only instance is set out on Before you connect.

Deleted on a clock

Your index is deleted within 30 days of you asking or of the account closing, and the account itself 90 days after that. Query logs go at 12 months. The full table is on Data & privacy.

Certifications

What we do not have

No SOC 2 report and no ISO 27001 certificate. Neither audit has been done. If your procurement process requires one, it is better that you know now than at the end.

What exists instead is on this page, and it is contractual rather than promotional: the four locks, the columns left out of the capture query, keys tied to one seat, live access off until you turn it on, and every query written down. The Data Processing Agreement gives you an audit of your own once in twelve months — sooner if a regulator asks or something goes wrong — and commits us to telling you about a breach without undue delay.

Data & privacy

What we hold, on its own page

This page is about how read-only is enforced. What we hold about you, where it lives and how to have it deleted has its own page.

Data & privacy