Why use the Trust Center?
Security and compliance due diligence is a normal part of working with any software vendor. The Trust Center is designed to make that process straightforward by putting key information in one place, without requiring you to go back and forth with a sales or support team just to get started.
You might use the Trust Center if you:
Are evaluating Tibo Energy and need to assess our security and compliance posture
Need to complete an internal vendor risk assessment
Want to verify our certifications or review our security policies
Are responsible for compliance or procurement at your organization and need documentation for your records
Have received a request from an auditor or regulator and need supporting evidence from your software vendors
Available documentation
The Trust Center provides an overview of the types of security and compliance documentation Tibo Energy maintains. This includes, but is not limited to:
ISO 27001 certificate — Confirms our certification status under the international standard for information security management
Statement of Applicability (SoA) — Outlines which ISO 27001 controls apply to Tibo Energy and how they are implemented
Penetration test summary — A high-level overview of our most recent third-party penetration test and its outcomes
Audit reports — Reports from external audits of our security controls and processes
Security policies — Documentation of our internal policies covering areas such as access control, incident response, and data handling
Privacy statement — Details on how Tibo Energy collects, uses, and protects personal data
Visit tibo.energy/trust-center to see what is currently available.
Requesting documents
Every document listed in the Trust Center can be requested directly from the Tibo Energy Security Team. Here is how the process works:
Submit your request — Use the Trust Center to identify the document you need and submit a request to the Security Team.
Review by the Security Team — All requests are reviewed before any documents are shared. This step ensures the right information goes to the right people.
Document access — Once approved, the document will be shared with you. Keep in mind:
Some documents are publicly available and can be shared without restrictions
Others contain sensitive information and require additional steps before they can be released
Certain documents — such as detailed audit reports or penetration test findings — require you to sign a Non-Disclosure Agreement (NDA) before they are shared
NDA process — If an NDA is required for the document you have requested, the Security Team will provide it as part of the request process. You do not need to source or draft your own.
Additional security requests
If you need information that is not explicitly listed in the Trust Center, you can still reach out to the Security Team directly. This includes:
Vendor security questionnaires (VSQs) — commonly required as part of procurement or risk assessment processes
Assurance requests — where you need confirmation or evidence related to a specific control or practice
Custom compliance documentation requests — such as evidence packs for specific regulatory frameworks
All additional requests are subject to review by the Security Team. Depending on the nature of the request and the information involved, an NDA may also be required before responses are shared.
To contact the security team use [email protected]
