Security & Trust
Effective 15 August 2026 ยท Creator OS
Security and privacy are built into Creator OS from day one. This page summarises the controls we operate and our compliance posture. We describe our status honestly โ controls that are live are marked as such, and formal certifications still on our roadmap are labelled accordingly.
Controls in place
| Area | Control | Status |
|---|---|---|
| Encryption in transit | TLS 1.2+ everywhere, HSTS enforced | โ Live |
| Sessions | HMAC-signed, HttpOnly, Secure, SameSite cookies | โ Live |
| HTTP hardening | CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy; server tokens off | โ Live |
| Access control | Least-privilege DB role; isolated per-service OS user; owner-gated dashboards | โ Live |
| Payment data | Handled by a PCI-DSS compliant gateway; we never store full card numbers | โ Live |
| Secrets | Kept outside source control, restricted file permissions, rotated on exposure | โ Live |
| Backups & recovery | Database backups with point-in-time restore | ๐ก Rolling out |
| Logging & monitoring | Application and access logging; anomaly alerting | ๐ก Rolling out |
Application security
The application is developed against the OWASP Top 10: parameterised database access (no string-built SQL), output encoding, CSRF-resistant same-site cookies, authorization checks on every owner action, and input validation on all mutations. Dependencies are kept current and monitored for known vulnerabilities.
VAPT (penetration testing)
We run internal security reviews and are scheduling an independent Vulnerability Assessment & Penetration Test. Our target is at least an annual third-party VAPT plus testing on major releases. A summary report will be made available to enterprise customers under NDA once the first external assessment is complete. Status: aligned, first external VAPT on roadmap โ not yet independently certified.
SOC 2 alignment
We operate against the SOC 2 Trust Services Criteria (Security, Availability, and Confidentiality) and maintain the underlying controls, policies, and evidence. A formal SOC 2 Type II examination by an independent auditor is planned. Status: controls aligned / audit-ready โ we are not yet SOC 2 certified and do not claim to be.
India data-protection compliance
Creator OS is designed to comply with the Digital Personal Data Protection Act, 2023 and the IT Act, 2000 & IT Rules, 2021: consent-based processing with easy withdrawal, Data Principal rights (access, correction, erasure, nomination), data minimisation, a published Grievance Officer, retention limits with deletion on inactivity, and verifiable parental consent handling for minors. On a reportable personal-data breach we will notify the Data Protection Board of India and affected users within the timelines required by law.
Data residency & retention
Personal data is primarily stored and processed in India. We retain data only as long as needed for the service or as required by law, and delete or anonymise it thereafter. See our Privacy Policy.
Responsible disclosure
Found a vulnerability? Please report it privately to legal@starvoxlabs.io with steps to reproduce. We commit to acknowledge within 3 business days, work with you on a fix, and not pursue good-faith researchers who follow this policy. Please do not access other users' data or degrade the service while testing.
Contact
Security questions: legal@starvoxlabs.io ยท Privacy: legal@starvoxlabs.io ยท Entity: StarvoxLabs Pvt. Ltd..
Questions about this document? Contact legal@starvoxlabs.io.