Kre8AI
Security and data protection

What happens to your documents, in plain terms.

Kre8AI processes internal policy material, so how we handle it matters more than any feature we could describe. This page is written for the people who have to approve us: IT, security, risk and legal.

  • ISO 27001

    SynrgiseLearn is certified. Kre8AI runs under that ISMS.

  • POPIA-aligned

    Information security policy and incident process designed for personal information.

  • Customer content

    Processed only to provide the service. Isolation, retention and our POPIA position are on this page.

Certifications and continuity

Operated under SynrgiseLearn's ISMS

Kre8AI is a SynrgiseLearn product. Security governance, business continuity and incident handling sit in the parent company's Information Security Management System.

SynrgiseLearn is ISO 27001 certified. The Information Security Policy defines access control on a need-to-know basis, leavers and privilege reviews, password standards, security awareness for staff, and formal handling of security incidents. The ISMS Policy Owner is Xenothan Hojem, Group CTO.

We align that programme with the Protection of Personal Information Act. Certificate details, statement of applicability and deeper control evidence are available on request for a security assessment.

Business continuity plan

Covers site, systems and people unavailability, with defined escalation and recovery procedures for critical services.

Backups and failover

Off-site backups, secondary data-centre switchover procedures, and periodic recovery testing. Exact product recovery targets are confirmed in writing for procurement reviews.

Testing cadence

Scenario-based continuity drills twice a year, an annual full BCP review, and monthly checks of backup integrity and failover capability.

AI features

Your content is used to run the feature you asked for

Authoring and media features process the material you submit so the product can generate, retrieve and render a course. That processing is limited to providing the service.

Customer content is not used to train foundation models. Hosting, residency and processing detail for your environment are confirmed in writing for a procurement review — we will not invent those details here.

Isolation

Tenant separation

Kre8AI is multi-tenant by design, but not shared-workspace by accident. There is no cross-tenant content.

  • Every record that belongs to a customer carries an organisation identifier, and every authenticated request is scoped to the caller’s organisation.
  • Uploaded documents and generated media are stored under per-organisation object storage namespaces.
  • Access within an organisation is role-based, and external reviewers reach only the single course they were invited to.

The product surface is served over HTTPS. Hosting provider, data residency region, encryption-at-rest mechanisms and backup retention for your environment are confirmed in writing for security questionnaires — we will not invent those details here.

Retention and deletion

How long we keep things, and how you get them removed

Source documents, generated courses, exported packages and related product records are retained for the life of your organisation's account and contract, unless you ask us to delete them earlier or your agreement sets a shorter period.

On contract termination, or when you request deletion, we remove customer content from the live systems under our deletion process. Backup copies fall out of the retention cycle according to that process; exact timeframes and any lag are stated in the customer agreement or confirmed in writing for a procurement review.

Data subject requests under POPIA are handled through our incident and compliance process. Contact us and we will action the request; turnaround commitments for your programme are confirmed in the operator agreement.

Accountability

The audit trail

Kre8AI records AI-assisted and human actions against each course, which is the record you produce when someone asks who wrote the content.

Generation events, review decisions, comments and approvals are all recorded with the actor and timestamp. See how governance works.

Incident response

Security incidents are reported, recorded and evaluated under the Information Security Policy. Where a personal-data security breach must be notified to the supervisory authority, we aim to do so without delay and no later than 72 hours after becoming aware of it. Material incidents that affect customers are communicated to the affected parties so they can take protective steps.

Staff access

SynrgiseLearn personnel access systems on a need-to-know basis under the ISMS. Access is granted for job function, reviewed periodically, and removed when roles change or people leave. Customer content is not treated as a shared browsing surface.

POPIA

Our position under the Protection of Personal Information Act

For the marketing website, SynrgiseLearn is the responsible party for personal information collected through forms and consented analytics. That processing is described in our privacy policy, including the Information Officer.

For documents and media you upload into Kre8AI, we act as an operator processing that content on your instruction to provide the service. You remain responsible for having a lawful basis to put the material into the product. A standard operator agreement is available for customers who need it in their procurement pack.

Need this for a procurement pack?

Send us your security questionnaire. We will answer in writing — including certificate evidence, hosting and residency detail, and a one-page security summary when you need something to attach.