Trust Center
Security status, controls and documents in one place.
Bibha recognises that the confidentiality, integrity and availability of the information and data we create, maintain and host are vital to our business and our partners' privacy. The Bibha AI Trust Center publishes our current security and compliance status and its listed controls. This page explains how to review that record and request documents.
Security and compliance status
These statuses were checked at the Bibha AI Trust Center on 2 October 2026. Use the live record for the latest status and request assurance documents with their scope and dates.

ISO 27001
Compliant
The Bibha AI Trust Center lists ISO 27001 as compliant. ISO 27001 is the international standard for an information security management system. Request the assurance documents and confirm their scope for your engagement.
Request the assurance documents relevant to your assessment.

SOC 2
Compliant
The Bibha AI Trust Center lists SOC 2 as compliant. Contact us for assurance documents, including the report type, scope and review period relevant to your assessment.
Confirm the report type, scope and dates with the Bibha team.

SOC 1
Compliant
SOC 1 examines a service organisation's internal controls over financial reporting, against the standards relevant to financial transactions. The Trust Center shows Bibha as SOC 1 compliant.

GDPR and UK GDPR
In progress
The General Data Protection Regulation governs how organisations protect personal data and privacy in the European Union, and UK GDPR is the United Kingdom's equivalent law. Bibha's programmes for both are in progress.
Our data protection page explains how Bibha handles personal data and how to exercise your rights.

ISO/IEC 42001:2023
In progress
ISO/IEC 42001:2023 is the management system standard for using AI responsibly, covering AI governance, risk management and compliance. The Trust Center lists Bibha's programme as in progress.

EU AI Act
In progress
The EU Artificial Intelligence Act is the European Union's risk-based regulation for AI systems. Bibha's conformity work is in progress.
What the Trust Center publishes
The Trust Center groups the controls Bibha has implemented into six categories, with a short statement of what each control does.
Product security
How Bibha finds, tracks and fixes vulnerabilities in its platform, reviews who can reach production systems and records security incidents.
Data security
How access to critical systems and production databases is approved, reviewed and removed, and how data is encrypted at rest and backed up.
Network security
How production networks are protected from unauthorised access and misuse, including deny-by-default firewalls and central collection of security logs.
App security
How changes to applications are approved and made securely, and how unauthorised activity is prevented.
Endpoint security
How staff devices that can reach critical servers or data are protected with anti-malware software and encryption.
Corporate security
The people and governance side of security: staff screening and awareness training, policy acknowledgement, risk assessment and review of third parties.
Open the live controls register to see every control and its description.
The Trust Center also links to the policies Bibha publishes: the privacy policy and terms of use on this website.
How to get documents
Bibha shares these documents through the Bibha AI Trust Center or on request:
- Current ISO 27001 assurance evidence
- Current SOC 2 assurance evidence
- Current SOC 1 assurance evidence
- Privacy policy and terms of use, published on this website and linked from the Trust Center
Request documents through the Trust Center, or through our contact page with the names of the documents you need. Audit reports may require a non-disclosure agreement before we share them.
Who runs the programme
On this page, "Bibha" means Bibha AI Labs Private Limited and its affiliate Bibha AI Inc. Both are bound by the policies published on this website.
- Bibha AI Labs Private Limited (CIN U62099KA2024PTC193869), Villa 92, JRC Palladio, Attibele Road, Billapura, Sarjapura, Anekal, Bangalore 562125, Karnataka, India. Headquarters and operator of bibha.ai.
- Bibha AI Inc., 3790 El Camino Real, Ste 853, Palo Alto, CA 94306, United States. US affiliate and contact point for US residents.
- Data Protection Officer: Prashant Kumar, at dpo@bibha.ai, for data protection, privacy and security questions.
Our security.txt file at bibha.ai/.well-known/security.txt follows the RFC 9116 standard and names dpo@bibha.ai as the security contact for researchers and automated tools.
Where to find what
| Need | Where | Who to contact |
|---|---|---|
| Security questions and vendor reviews | Security page and the Bibha AI Trust Center | Data Protection Officer, dpo@bibha.ai |
| Audit reports and certificates | Bibha AI Trust Center | Bibha team, through the contact page |
| Data protection and privacy requests | Data protection page and privacy policy | Privacy contact, privacy@bibha.ai |
| Data residency | Data residency page | Data Protection Officer, dpo@bibha.ai |
| Cookies and analytics | Cookie policy, and Cookie settings at the bottom of every page | Privacy contact, privacy@bibha.ai |
| Vulnerability reports | security.txt at bibha.ai/.well-known/security.txt | Data Protection Officer, dpo@bibha.ai |
Where to find security, privacy and compliance information
- Need
- Security questions and vendor reviews
- Where
- Security page and the Bibha AI Trust Center
- Who to contact
- Data Protection Officer, dpo@bibha.ai
- Need
- Audit reports and certificates
- Where
- Bibha AI Trust Center
- Who to contact
- Bibha team, through the contact page
- Need
- Data protection and privacy requests
- Where
- Data protection page and privacy policy
- Who to contact
- Privacy contact, privacy@bibha.ai
- Need
- Data residency
- Where
- Data residency page
- Who to contact
- Data Protection Officer, dpo@bibha.ai
- Need
- Cookies and analytics
- Where
- Cookie policy, and Cookie settings at the bottom of every page
- Who to contact
- Privacy contact, privacy@bibha.ai
- Need
- Vulnerability reports
- Where
- security.txt at bibha.ai/.well-known/security.txt
- Who to contact
- Data Protection Officer, dpo@bibha.ai
Frequently asked questions
Is Bibha SOC 2 compliant?
The Bibha AI Trust Center lists SOC 2 and SOC 1 as compliant. Request the assurance documents to confirm the report type, scope and review period relevant to your assessment.
Is Bibha ISO 27001 certified?
The Bibha AI Trust Center lists ISO 27001 as compliant. Request the current assurance documents to confirm certificate details, scope and validity for your assessment.
What is Bibha's GDPR status?
Bibha's GDPR and UK GDPR programmes are in progress, and the Bibha AI Trust Center shows their live status. Our data protection page explains how Bibha handles personal data and how to exercise your rights.
How do I get Bibha's SOC 2 report?
Request it through the Bibha AI Trust Center, or through our contact page with the name of the report you need. Audit reports may require a non-disclosure agreement before we share them.
Does the Trust Center cover TalentFlow, ReachFar and PeachDesk?
TalentFlow, ReachFar and PeachDesk are built on Bibha. Request assurance documents to confirm which products, systems and activities are covered by their scope. Each product's privacy notice or your organisation's agreement with Bibha sets the terms for that product.
How often is the Trust Center updated?
The Trust Center is the current public record. This page records the status on its last reviewed date. Use the live register for your vendor assessment.