Trust Center
Built for trust. Verified, transparent, audit-ready.
HiBFF is used by parents, teens, schools, and corporate wellbeing teams. We treat that responsibility seriously. Everything below — uptime, privacy, security, accessibility, compliance — is verifiable by you, today, without needing to email anyone.
Live status
Real-time uptime, component-by-component, last 90 days of incidents.
Open status pageSecurity policy
Responsible-disclosure policy, scope, safe-harbour, hall of fame.
Read policyPrivacy policy
What we collect, why, who we share with, and your rights under GDPR/CCPA/COPPA.
Read privacyTerms of Service
The agreement that governs your use of HiBFF, including B2B licensing.
Read termsAccessibility
WCAG 2.1 AA · UK Public Sector Bodies Regulations · EAA. Reporting workflow.
StatementSubprocessors
The full list of vendors that process HiBFF data (Postmark, Twilio, Atlas, etc).
View listService-level commitment
Our 99.9 % uptime target, last 12 months actuals, compensation policy.
View SLATeen Charter
The promises we make directly to the teens who use AvA.
Read chartersecurity.txt
RFC 9116 — discoverable security contact for scanners and researchers.
View security.txtPostmortems
Public RFC-style write-ups of any service incidents we've had.
View postmortemsContact us
Procurement, security, partnerships, press — all routed to a real human.
Get in touchCompliance & certifications
Data Protection Act 2018, ICO-registered.
EU Representative arrangement; lawful basis documented per processing activity.
Parent consent, age-gated AvA personality, US-specific data minimisation.
Tested with NVDA, VoiceOver, axe DevTools, manual keyboard pass.
California consumer rights honoured globally; do-not-sell respected.
HTTPS everywhere, JWT auth, rate-limited APIs, MongoDB Atlas at-rest encryption.
Evidence collection in progress (audit logs, change management, vendor reviews).
Mapping 27002 controls; targeting 2026 certification.
Onboarding kit drafted for Singapore B2B partners.
Your data, your control
Already a HiBFF user? Download every byte we hold on you, or trigger the full erasure workflow — both right from your account settings, no email tickets required.
Embed our live status
Drop the live status badge into your pitch deck, partner page, or README. It's a 200-byte SVG that updates automatically and links straight to the full status page.
<a href="https://hibff.com/status"> <img src="https://hibff.com/api/status/badge.svg" alt="HiBFF status" /> </a>
Procurement, security, or compliance question?
We answer enterprise security questionnaires within 5 business days. Bug reports get a response within 2.