Creative Media logo Creative MediaTRUST CENTER

CREATIVE MEDIA TRUST CENTER

Trust through transparent standards.

Creative Media publishes and distributes content across books, eBooks, audiobooks, magazines, apps, and music. This Trust Center documents the principal standards, frameworks, identifiers, assurance programs, and regulatory requirements relevant to those products and to our supporting technology.

i

Certification claims are evidence-based.

Reference to a standard does not mean Creative Media is certified, audited, or independently attested against it. A certification or attestation is shown as held only when verified evidence has been published. Otherwise the status is explicitly listed as Not publicly asserted, Reference baseline, or Applicable when in scope.

ASSURANCE DIRECTORY

Certifications & independent attestations

Programs a modern print-and-digital publisher may use to demonstrate third-party assurance. Current public status is intentionally conservative.

Not publicly asserted

ISO/IEC 27001

Information Security Management System certification.

Not publicly asserted

ISO/IEC 27701

Privacy Information Management System certification.

Not publicly asserted

ISO 22301

Business Continuity Management System certification.

Not publicly asserted

SOC 2 Type I / Type II

Independent CPA attestation against applicable Trust Services Criteria; this is an attestation, not a certification.

Applicable when in scope

PCI DSS validation

Assessment or self-assessment evidence for environments that store, process, transmit, or can affect cardholder data.

Not publicly asserted

ISO 9001

Quality Management System certification for repeatable quality processes.

Not publicly asserted

ISO 14001

Environmental Management System certification.

Supplier / chain option

FSC / PEFC Chain of Custody

Traceability certifications relevant to paper and print supply chains when certified materials are specified.

STANDARDS REGISTER

Publishing, technology & regulatory standards

This register covers major cross-industry and media-specific references. Applicability varies by product, market, data flow, retailer, distributor, and customer.

Standard / frameworkCategoryPrimary scopePublic posture

CONTROL OBJECTIVES

How trust is organized

These objectives describe the control domains expected for Creative Media's publishing and technology environment. They are not a substitute for a third-party audit report.

01

Identity & access

Centralized identity, strong authentication, least privilege, role separation, periodic access review, and protected administrator workflows.

02

Infrastructure & application security

Secure configuration, HTTPS, dependency management, vulnerability remediation, logging, change control, and risk-based application security testing.

03

Privacy & data lifecycle

Data minimization, purpose limitation, retention rules, deletion workflows, data-subject rights support, and special care for children's data where applicable.

04

Accessibility by design

Accessible content structures, alternative text, keyboard support, readable contrast, semantic metadata, and product-level accessibility testing.

05

Publishing integrity

Identifier governance, metadata quality, edition/format separation, rights and territorial controls, provenance, corrections, and distribution consistency.

06

Vendor & supply-chain governance

Risk-tiered suppliers, contract controls, subprocessors, secure software dependencies, printer/distributor requirements, and continuity considerations.

07

Incident response

Detection, triage, containment, evidence preservation, recovery, stakeholder communication, root-cause review, and corrective actions.

08

Business continuity

Backups, recovery objectives, tested restoration, platform redundancy where appropriate, supplier dependencies, and documented continuity procedures.

09

Rights, copyright & licensing

Ownership and license records, permissions, takedown workflows, royalty/source metadata, territorial rights, and responsible use of third-party content.

FORMAT-SPECIFIC TRUST

One publisher, multiple delivery chains.

Each media type has different technical and commercial controls. Creative Media's Trust Center keeps those requirements visible rather than treating publishing as a single-format workflow.

Books & printISBN · ONIX · BISAC/Thema · PDF/X · ISO print process control · responsible paper sourcing
eBooksEPUB 3.3 · EPUB Accessibility 1.1 · WCAG · accessibility metadata · retailer validation
AudiobooksW3C Audiobooks · ONIX · DDEX audiobook profiles where used · audio QC · retailer delivery requirements
MagazinesISSN · DOI where used · PDF/X · PDF/UA · print color/process controls · accessibility
Apps & webOWASP ASVS/MASVS · NIST SSDF · WCAG · privacy-by-design · app-store platform requirements
MusicISRC · ISWC · DDEX ERN · GS1 identifiers where used · rights/territory metadata · audio delivery QC

RESPONSIBLE DISCLOSURE

Report a security or privacy concern.

If you believe you found a vulnerability, privacy issue, rights problem, or accessibility barrier involving a Creative Media service, please contact us with enough detail to reproduce and assess it. Do not access, alter, download, or disclose data beyond what is necessary to demonstrate the issue.

EVIDENCE & REVIEWS

Trust documentation

Security documentation

Architecture, access, change, logging, incident, and recovery controls are maintained as operational documentation. Public summaries are published here when appropriate.

Accessibility documentation

Product accessibility metadata and testing evidence should travel with applicable digital products and be updated when formats change.

Supplier documentation

Printer, distributor, cloud, payment, and software suppliers may require separate attestations or certifications based on scope.

Review cadence

Standards and regulatory references are reviewed as specifications evolve. This page was last materially reviewed .