Comparison Overview

Creative Virtual

VS

Carelon Global Solutions India

Creative Virtual

167 Cannon Workshops, London, undefined, E14 4AS, GB
Last Update: 2025-05-05 (UTC)

Strong

Creative Virtual is a conversational AI leader recognised in the industry for our nearly two decades of experience and unmatched expertise. Our innovative V-Personโ„ข virtual agent, chatbot, and live chat solutions bring together humans and AI to deliver seamless, personalised, and scalable digital support for customers and employees. Leading global organisations rely on our award-winning technology and expert consultation to improve their support experience, reduce costs, increase sales, and build brand loyalty. Our global team and extensive partner network support installs around the world in over 37 languages, providing both localised collaboration and international insights. Creative Virtual is headquartered in the United Kingdom with operations in the United States, Australia, India, Singapore and Hong Kong.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 61
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Carelon Global Solutions India

Indianapolis, Indianapolis, Indiana, 46204, US
Last Update: 2025-02-21 (UTC)

Strong

Between 800 and 900

Carelon Global Solutions makes healthcare operations more practical, effective, and efficient. Our global team of more than 25K innovators drives growth, delivers exceptional support, and develops digital tools specifically for health plans, providers, and systems. Each day, our partners and experts from across the globe implement new ways to save time and money โ€” so doctors can focus on care. Formerly known as Legato Health Technologies, Carelon Global Solutions is part of the Carelon family of brands and is a fully owned subsidiary of Elevance Health. Headquartered in the United States, Carelon Global Solutions has talented teams in India, Ireland, the Philippines, and Puerto Rico. Want to be part of something meaningful? Join our growing team. We believe that when bold talent meets limitless thinking, the possibilities are endless. As part of our India team, youโ€™ll work alongside some of the best minds in the business to solve healthcareโ€™s most complex challenges. Youโ€™ll be part of an exciting, fast-paced, and supportive company culture, where all associates receive: โ€ข Competitive pay. โ€ข Generous benefits. โ€ข Training, mentorship, and growth. โ€ข Hybrid workplace flexibility. โ€ข The opportunity to help others and make a difference. Follow our Carelon Global Solutions India LinkedIn page for the latest job postings and timely company news.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 15,206
Subsidiaries: 21
12-month incidents
0
Known data breaches
5
Attack type number
3

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/creative-virtual.jpeg
Creative Virtual
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/carelon-global-solutions-in.jpeg
Carelon Global Solutions India
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
Creative Virtual
100%
Compliance Rate
0/4 Standards Verified
Carelon Global Solutions India
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Creative Virtual in 2025.

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Carelon Global Solutions India in 2025.

Incident History โ€” Creative Virtual (X = Date, Y = Severity)

Creative Virtual cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” Carelon Global Solutions India (X = Date, Y = Severity)

Carelon Global Solutions India cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/creative-virtual.jpeg
Creative Virtual
Incidents

No Incident

https://images.rankiteo.com/companyimages/carelon-global-solutions-in.jpeg
Carelon Global Solutions India
Incidents

Date Detected: 10/2022
Type:Breach
Blog: Blog

Date Detected: 10/2021
Type:Breach
Attack Vector: Theft
Blog: Blog

Date Detected: 8/2021
Type:Breach
Attack Vector: Physical Break-In (Vendor Office)
Blog: Blog

FAQ

Both Creative Virtual company and Carelon Global Solutions India company demonstrate a comparable AI risk posture, with strong governance and monitoring frameworks in place.

Carelon Global Solutions India company has historically faced a number of disclosed cyber incidents, whereas Creative Virtual company has not reported any.

In the current year, Carelon Global Solutions India company and Creative Virtual company have not reported any cyber incidents.

Carelon Global Solutions India company has confirmed experiencing a ransomware attack, while Creative Virtual company has not reported such incidents publicly.

Carelon Global Solutions India company has disclosed at least one data breach, while Creative Virtual company has not reported such incidents publicly.

Carelon Global Solutions India company has reported targeted cyberattacks, while Creative Virtual company has not reported such incidents publicly.

Neither Creative Virtual company nor Carelon Global Solutions India company has reported experiencing or disclosing vulnerabilities publicly.

Carelon Global Solutions India company has more subsidiaries worldwide compared to Creative Virtual company.

Carelon Global Solutions India company employs more people globally than Creative Virtual company, reflecting its scale as a IT Services and IT Consulting.

Latest Global CVEs (Not Company-Specific)

Description

pwn.college DOJO is an education platform for learning cybersecurity. In versions up to and including commit 781d91157cfc234a434d0bab45cbcf97894c642e, the /workspace endpoint contains an improper authentication vulnerability that allows an attacker to access any active Windows VM without proper authorization. The vulnerability occurs in the view_desktop function where the user is retrieved via a URL parameter without verifying that the requester has administrative privileges. An attacker can supply any user ID and arbitrary password in the request parameters to impersonate another user. When requesting a Windows desktop service, the function does not validate the supplied password before generating access credentials, allowing the attacker to obtain an iframe source URL that grants full access to the target user's Windows VM. This impacts all users with active Windows VMs, as an attacker can access and modify data on the Windows machine and in the home directory of the associated Linux machine via the Z: drive. This issue has been patched in commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef. No known workarounds exist.

Risk Information
cvss4
Base: 9.5
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browse to the page containing the vulnerable field. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browse to the page containing the vulnerable field. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimโ€™s browser when they browse to the page containing the vulnerable field. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description

Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.

Risk Information
cvss3
Base: 3.1
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N