• ISO 27001 certified · Updated May 2026

Security you can audit, not assume.

Our Trust Center is where you go for the proof. Certifications, audit reports and policies – request what you need and we’ll send it over.

  • ISO 27001:2022

  • Annual pentest

  • EU-hosted
certifications & audits

Independent proof, on request.

ISO 27001 Certificate

Our active certification for information security management

Statement of Applicability

Annex A controls – what applies to Tibo and how.

Pentest Summary

Latest third-party penetration test report. Scope and findings.

Internal Audit Report

Most recent internal audit, findings and follow ups.

External Audit Report

Independent surveillance audit by our certification body.

NIS 2

Not yet in scope for Tibo. We track NIS 2 readiness – request a status note.

policies

How we actually operate.

AI Policy

How our AI components are governed, monitored and constrained.

Digital Access Policy

Identity, access provisioning, MFA, joiner-mover-leaver controls.

Information Protection Policy

Classification, handling and encryption of customer and company data.

Secure System Development Policy

SDLC, code review, secrets, dependency and supply-chain controls.

Vulnerability & Patch Management

How we detect, prioritise and remediate vulnerabilities.

Privacy statement

How we collect, process and protect personal data.

Need something that isn’t listed?

Vendor questionnaires, subprocessor lists, custom assurance requests — our security team handles them directly. We aim for a one-business-day turnaround.