Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
F Creative Studio 360
Security and trust

Security, Trust & Transparency

At F Creative Studio 360, we recognize that protecting information, maintaining secure systems and managing operational risks are essential to building trusted technology solutions. Our Trust Center provides visibility into our security approach, relevant frameworks and publicly available security documentation.

Security is part of how engagements are designed, built, and operated. This page sets out the practices, the public documents, and the standards that guide the work.

Overview

A security programme with a clear public record

Security practices
6 Published documents
In force Disclosure policy
Published Privacy and cookie notices

Practices, documents, and contacts on this page are the public face of the security programme.

Practices in the programme

Access, application security, data protection, monitoring, continuity, and response are part of how systems and client work are handled.

Documents you can read

The vulnerability disclosure policy, privacy notice, cookie notice, terms, and accessibility statement are published and linked below.

Standards that guide the work

NIST CSF 2.0, CIS Controls, OWASP, ISO/IEC 27001, and the SOC 2 Trust Services Criteria inform the programme. Naming a standard is guidance, not a certificate.

Vulnerability reports
Disclosure policy

Security practices

How the programme is run

Each practice below is part of the way F Creative Studio 360 protects systems, information, and client work.

Access Control

Access is granted for the work a person needs to do, approved before it is given, and removed when that need ends.

How this is applied

Accounts are individual. Privileges follow the role, and access is withdrawn when the role or the engagement ends.

Application Security

Changes are reviewed for injection, access-control, and dependency weaknesses before they are released.

How this is applied

Design and review use common web risk categories, including the OWASP Top 10, as a checklist. Findings are fixed or accepted before a change is relied on.

Data Protection

Information is collected for a purpose, limited to the people who need it, and kept only as long as that purpose requires.

How this is applied

The published privacy policy is the notice for this website. Client information is handled under the engagement that covers it.

Vulnerability Management

Known weaknesses are identified, prioritised, and tracked until they are fixed or accepted.

How this is applied

External reports go to security@fcreativestudio360.com under the published vulnerability disclosure policy.

Incident Response

Suspected incidents are reported to the security team, contained, and recorded by people who can act.

How this is applied

The published disclosure policy is the public route. Client incidents are handled under the engagement.

Security Monitoring

Security-relevant activity is logged, and someone is accountable for reviewing it.

How this is applied

Hosting and application logs are available when an event needs to be understood and followed up.

Business Continuity

Important work is set up so it can continue, or be restored, after a disruption.

How this is applied

Recovery expectations are agreed in the engagement, including what is in scope and how quickly it needs to return.

Secure Development

Design, coding, review, and release include security checks that match the risk of the change.

How this is applied

Dependencies, access, and input handling are reviewed before a change is relied on.

Vendor Risk Management

Suppliers who can affect our systems or client information are identified and reviewed before they are relied on.

How this is applied

Hosting and other suppliers are chosen for the work they support. Toolkit logos elsewhere on this site are product marks, not security attestations.

AI Governance

AI use has an owner, a permitted purpose, and limits on the data and actions a system may take.

How this is applied

Client AI work is scoped in the engagement, including which data a system may use and which actions it may take.

No practices match this status.

Framework references

Standards that shape the programme

These public standards inform how security work is designed. The names are guidance. They are not certificates or independent audit reports.

NIST

Reference standard

NIST Cybersecurity Framework 2.0

Purpose. A voluntary outcome-based framework for identifying, protecting, detecting, responding to and recovering from cybersecurity risk.

Domain. Enterprise cybersecurity programme governance.

How it guides the work. Programme work is organised around identify, protect, detect, respond, and recover.

Official documentation

CIS

Reference standard

CIS Critical Security Controls v8.1

Purpose. A prioritised set of safeguards for common attack techniques.

Domain. Safeguard implementation and measurement.

How it guides the work. Safeguards are selected to match the systems in an engagement.

Official documentation

OWASP

Reference standard

OWASP Top 10

Purpose. Awareness of the most common web application risk categories.

Domain. Application security.

How it guides the work. Web application reviews use these risk categories as a checklist.

Official documentation

ASVS

Reference standard

OWASP ASVS

Purpose. A verification standard with testable application-security requirements.

Domain. Application security verification.

How it guides the work. Application reviews can be checked against testable requirements. No ASVS level is claimed.

Official documentation

ISO

Reference standard

ISO/IEC 27001:2022

Purpose. Requirements for an information security management system. Certification is issued by an accredited body, not by using the standard’s name.

Domain. Information security management.

How it guides the work. Security management follows a managed-system approach. F Creative Studio 360 is not ISO/IEC 27001 certified.

Official documentation

SOC 2

Reference standard

SOC 2 Trust Services Criteria

Purpose. Criteria used by an independent CPA firm when it examines controls relevant to security, availability, processing integrity, confidentiality or privacy.

Domain. Independent examination of controls.

How it guides the work. Control design can follow the Trust Services Criteria. F Creative Studio 360 has not published a SOC 2 Type II report.

Official documentation

Responsible disclosure

Report a suspected vulnerability

Send suspected vulnerabilities to the security team. Reports are handled under the published disclosure policy.

Email security@fcreativestudio360.com

Read the Vulnerability Disclosure Policy

What to include

Describe the issue, the URL or system, and the steps to reproduce it. Keep proof benign. Stop if you see personal or client data. The policy lists the full set of details.

Secure reporting

Send the first message to security@fcreativestudio360.com. If the report contains exploit detail or credentials, say so briefly and wait for a more private channel. Do not post the detail publicly first.

Scope and authorization

The policy covers systems F Creative Studio 360 owns or operates. It does not authorize testing of client environments, denial-of-service, social engineering, or unlawful activity.

Coordinated disclosure

Give us a chance to investigate before public discussion. Communication expectations, including any acknowledgement timing and the limits of legal comfort, are only those written in the published policy.

Privacy and data handling

Information is handled with a stated purpose

Personal information on this website is handled under the published privacy policy. The principles below are how that handling is organised.

Data minimization

Collect and keep only what a stated purpose needs.

Purpose limitation

Use information for the purpose it was collected for, unless a further use is explained in the privacy policy or agreed.

Access restriction

Limit access to the people who need the information for their work.

Retention and disposal

Keep information for the period the purpose requires, then dispose of it.

Privacy requests

Questions about personal information on this website go through the contact on the privacy policy.

Service providers

Hosting and other suppliers that support the website are covered by the privacy notice.

The public site is served over HTTPS. Security reports use the mailbox on this page.

Privacy Policy · Terms · Cookies

Contact

Talk to the right address

Security reports, privacy questions, and general enquiries each have a published route.