COMPLIANCE & CERTIFICATIONS
Where we are. Where we are going. Honestly.
We do not claim certifications we do not yet hold. Here is the actual posture.
This page states JibeONE's compliance posture honestly and without overstatement. We describe what is in place today, what is in progress, and how we approach the major regulatory regimes. We do not claim certifications we do not hold.
1. Current attestations
JibeONE does not currently hold a completed third-party security certification or attestation. We will not describe ourselves as "SOC 2 certified" or equivalent until an independent report exists, and this page will be updated when one does.2. In progress
- SOC 2. We are building toward a SOC 2 examination. Our technical control set (single-store authentication, mandatory two-factor authentication, role-based access control, fail-closed authorization, encryption in transit, audit logging, dependency scanning in the deploy pipeline) is substantially in place; the remaining work is the formal governance program and the observation period an auditor tests. We are targeting Type I readiness first, followed by a Type II observation window.
- Governance program. We are formalizing the security policies, risk register, vendor-management, incident-response, and business-continuity documentation that a SOC 2 report evaluates.
3. Regulatory readiness
- GDPR. We offer a Data Processing Addendum with Article 28 processor terms, Annex II security measures, and Standard Contractual Clauses incorporated by reference for cross-border transfers. See our Privacy Policy and Sub-processors page.
- CCPA / CPRA. We do not sell or share personal information as those terms are defined, and we support the access, deletion, and correction rights described in our Privacy Policy.
- HIPAA. JibeONE is not a certified healthcare platform. Its on-premises and private-cloud deployment model lets a covered entity or business associate operate it within their own compliant environment; a Business Associate Agreement would be handled contractually where applicable.
- FERPA. Where an educational institution deploys JibeONE within its own environment, the institution remains the controller of education records; JibeONE processes such data only on the institution's instructions.