Security, compliance, and AI governance

Enterprise voice AI security, certified and verifiable

Bibha, the company behind PeachDesk, is ISO 27001 certified and SOC 2 Type 1 and Type 2 attested. The controls behind GDPR, ISO/IEC 42001, and the EU AI Act are implemented and operating across the platform today, with final independent audits underway and every status published live at the Bibha AI Trust Center. Teams that want call data inside their own perimeter can self-host PeachDesk behind their own identity and compliance stack.

ISO 27001 certified badgeSOC 2 Type 2 attestation badge

Independent audits and certifications

Bibha, the company behind PeachDesk, is ISO 27001 certified and SOC 2 Type 1 and Type 2 attested. The controls behind GDPR, UK GDPR, ISO/IEC 42001, and the EU AI Act are implemented and operating today, with final independent audits in progress. Every status, with its evidence, is published live at the Bibha AI Trust Center.

Attested and certified

ISO 27001 certified badge

ISO 27001

Certified

Bibha is certified to ISO 27001, the globally recognized standard for establishing, implementing, maintaining, and continually improving an information security management system. The certification covers the ISMS behind the platforms we build and operate, including PeachDesk.

SOC 2 Type 2 attestation badge

SOC 2 Type 2

Attested

Bibha holds a SOC 2 Type 2 report, the AICPA attestation standard for service organizations. The audit examines how our controls operate over time across all five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

SOC 2 Type 1 report also available at the Trust Center.

Controls in place, final audits in progress

GDPR programme badge

GDPR

Final audit in progress

Every technical control GDPR expects of a voice AI platform is in place and operating: per-agent retention windows with automated purge, call data in storage you control, telemetry off by default. The final independent audit is underway.

UK GDPR programme badge

UK GDPR

Final audit in progress

The same operating controls extend to the UK's data protection requirements, run as a parallel programme alongside the EU GDPR work, with its final audit underway.

ISO/IEC 42001:2023 programme badge

ISO/IEC 42001:2023

Final audit in progress

Our AI management system, covering AI governance, risk management, and the responsible operation of AI systems, is implemented and running today. The final certification audit is in progress.

EU Artificial Intelligence Act programme badge

EU AI Act

Final audit in progress

The EU's risk-based AI regulation maps directly onto how PeachDesk already operates: documented AI governance, human control over every agent, and disciplined data handling. Final conformity work is underway.

Compliance status changes as audits complete, so this page does not carry dates or promises. For the live register and the evidence behind each attestation, visit the Bibha AI Trust Center.

AI governance and data privacy, built into the platform

Governance at PeachDesk is how the platform runs, not a policy PDF. Our AI management system operates in line with ISO/IEC 42001 and the EU AI Act, and the data privacy controls behind GDPR and UK GDPR ship in every deployment, hosted or self-hosted.

Your customer

Phone or browser call

PeachDesk voice AI

Agents, telephony, orchestration

Storage you control

MinIO or S3, signed time-limited URLs

  • Encrypted at rest, Fernet AES-128 with HMAC
  • Per-agent retention with automated purge
  • Telemetry off by default
  • Self-hosted: your perimeter, your keys
Call audio and transcripts move from the caller through PeachDesk into object storage the deployment controls. On a self-hosted deployment every step sits inside your environment.

AI governance

  • An AI management system that runs daily. Governance, risk management, and responsible-AI practices operate in line with ISO/IEC 42001, with the final certification audit in progress.
  • EU AI Act readiness. The regulation's risk-based controls map onto how PeachDesk already operates; final conformity work is underway.
  • Your team directs every agent. Behaviour and voice are defined by your team, and optional call and LLM traces route to your own Langfuse project, not ours.

Data privacy

  • GDPR and UK GDPR controls in place. The technical basis both laws expect ships in the platform today, with final audits in progress.
  • Retention on your terms. Per-agent windows with a scheduled purge of logs, recording and transcript references, and extracted data.
  • Residency by architecture. Self-hosting keeps personal data inside your perimeter; see voice AI data residency for the full picture.

Security controls, live in the codebase

Every control below ships in the PeachDesk codebase today. The Bibha AI Trust Center monitors the wider programme beyond the product, including corporate and endpoint controls, and publishes live status.

Access and identity

  • SSO, SAML, and MFA. Available on the enterprise plan.
  • Team roles. Teammates join as owner, admin, or member, with role checks on billing and membership routes.
  • Org-scoped API keys. Keys bind to one organisation and are stored only as SHA-256 hashes with a short display prefix, so the raw key never sits in the database.

Data protection

  • Credentials encrypted at rest. Provider credentials use Fernet, AES-128 with HMAC authentication, and sensitive telephony fields are masked when read back.
  • Your storage, signed URLs. Recordings and transcripts live in deployment-controlled object storage, self-hosted MinIO or S3 in the hosted cloud, served only behind signed, time-limited URLs.
  • Retention with automated purge. Operators set a retention window in days per agent, and a scheduled job purges expired logs, recording and transcript references, and extracted data.

Application security

  • Tenant isolation, guarded by CI. Request-path queries against organisation data run through org-scoped helpers, and a CI guard test fails the build if code queries org-scoped models without the filter, so isolation is a build-breaking invariant rather than a policy document.
  • Signed webhooks, verified callbacks. Webhooks are HMAC-signed over the raw body, and inbound telephony callbacks are checked for provider signature, timestamp, and nonce before acceptance.
  • Private vulnerability disclosure. A published SECURITY.md routes reports through GitHub Security Advisories, so researchers can report issues without exposing users.

Deployment control

  • Self-hosting keeps data inside your environment. Inference, models, and call data stay in your perimeter, fronted by your own identity and logging stack.
  • Telemetry off by default. Product telemetry stays inert unless the operator turns it on, and optional call and LLM traces route to the customer's own Langfuse project, not ours.
  • Short-lived TURN credentials. Browser calls connect through WebRTC relay credentials that expire, so each session gets time-limited credentials instead of a standing secret.

Controls reviewed against the codebase: August 2026.

Controls evolve as the codebase does; the live, continuously monitored view of the wider programme is on the controls tab of the Bibha AI Trust Center.

Your provider keys stay under your control

Bring-your-own-keys is a security boundary, not just a billing option. When you connect your own telephony and model provider accounts, the credentials are encrypted at rest with Fernet (AES-128 with HMAC authentication), usage is billed directly by your provider, and PeachDesk never meters, throttles, or gates those calls. Your spend and your provider relationship stay between you and them. See how voice AI BYOK works.

Peach, the PeachDesk mascot, holding the key to your own provider accounts

Working with your security team

Security reviews move faster when both sides work from evidence. Three ways to engage us directly.

  • Private vulnerability disclosure. Our repositories carry a SECURITY.md that routes reports through GitHub Security Advisories, so researchers can raise issues privately.
  • Privacy and data-processing questions. Our Data Protection Officer handles GDPR and privacy-rights inquiries: email the DPO. Our privacy policy covers what we collect and why.
  • Vendor reviews. Send your vendor questionnaire or threat model and we will answer from the code and the live record, not from a sales deck.
Peach, the PeachDesk mascot, working through a security questionnaire on a laptop

Is PeachDesk SOC 2 compliant?

Yes. Bibha, the company behind PeachDesk, maintains SOC 2 Type 2 compliance across security, availability, processing integrity, confidentiality, and privacy. The report and the controls behind it are published at the Bibha AI Trust Center. In the product, those controls are verifiable in code: tenant isolation guarded by a CI test, credentials encrypted at rest, and signed webhooks on every call event.

Is PeachDesk ISO 27001 certified?

Yes. Bibha, the company behind PeachDesk, is certified to ISO 27001 for its information security management system. ISO 27001 is the global standard for establishing, maintaining, and continually improving an ISMS, and the certificate is available at the Bibha AI Trust Center. Bibha also holds SOC 2 Type 1 and SOC 2 Type 2 reports, available at the Trust Center.

Does PeachDesk comply with GDPR?

PeachDesk ships every technical control GDPR expects of a voice AI platform, and Bibha's final GDPR audit is in progress, tracked live at the Bibha AI Trust Center. UK GDPR runs as a parallel programme. The controls are visible in the product: configurable per-agent retention with automated purge, call recordings and transcripts in storage you control, and telemetry that stays off unless you turn it on.

How does PeachDesk handle AI governance?

Bibha operates an AI management system aligned with ISO/IEC 42001, the international standard for managing AI responsibly, with the final certification audit in progress. EU AI Act readiness runs as a parallel programme, and both are published at the Bibha AI Trust Center. In the product, your team defines every agent's behaviour, telemetry is off by default, and optional traces route to your own Langfuse project.

Where do my call recordings and transcripts live?

In object storage the deployment controls, served through signed, time-limited URLs. PeachDesk stores call audio and transcripts in the deployment's own storage: self-hosted MinIO, or S3 in the hosted cloud. On a self-hosted deployment that bucket sits inside your environment, so recordings and transcripts never need to leave it. See voice AI data residency for the full picture across deployment modes.

How are my provider credentials and API keys protected?

Provider credentials are encrypted at rest with Fernet, AES-128 with HMAC authentication, and API keys are stored only as SHA-256 hashes. Each API key is scoped to one organisation and shown with a short display prefix. Webhook secrets get the same encryption, and sensitive telephony fields are masked when read back. With voice AI BYOK, your provider keys stay under your control: calls on your own keys are billed by your provider, never metered by PeachDesk.

Does PeachDesk support SSO, SAML, or MFA?

Yes. SSO, SAML, and MFA are available on the PeachDesk enterprise plan. The product also includes team roles, owner, admin, and member, with role checks on billing and membership routes. Teams that self-host can additionally front the deployment with their own identity provider, access policies, and logging, while inference and call data stay inside their environment.

Can we deploy voice AI inside our own environment for compliance?

Yes. PeachDesk self-hosting keeps inference, models, and call data inside your environment. Your identity provider, logging stack, retention policies, and perimeter controls front the deployment, so teams in regulated industries, including healthcare, can apply their own compliance frameworks end to end. We do not claim HIPAA compliance; self-hosting keeps call data under your own compliance programme. Details are on the self-hosted deployment page, and Bibha's current audit status is always public at the Bibha AI Trust Center.

Bring your questionnaire. We will bring the evidence.

Everything on this page is monitored live at the Bibha AI Trust Center, updated as audits land. Bring your hardest questions and put them to the people who run the platform.

Peach, the PeachDesk mascot, pointing the way to your security review

Talk to an expert

Tell us about your calls and we will come back with a straight answer on fit, sourcing, and deployment. Your message goes to the team at sales@bibha.ai.

Start free

Tell us where to reach you and what you are building, and we will set up your workspace access. Your message goes to the team at sales@bibha.ai.