generated: '2026-08-13' method: searched probe: true url: https://trust.bikky.com/ platform: Vanta certifications: - SOC 2 frameworks_referenced: - NIST (system design and security policies stated as aligned with NIST best practices) practices_published: - Customer data encrypted at rest - Regular vulnerability scanning - Regular penetration tests - Regular policy reviews - Customers own their data; stated compliance with US data privacy regulations evidence: - source: https://trust.bikky.com/ http_status: 200 kind: trust-center detail: >- Serves Bikky Trust Center and og:title "Bikky Trust Center" from the Vanta trust-report bundle (assets.vanta.com index-trust-report). DNS confirms provider ownership: trust.bikky.com is a CNAME to 662bd7f45360cc947af486cc.cname.vantatrust.com. - source: https://www.bikky.com/ http_status: 200 kind: security-section detail: >- Homepage "Security & privacy" section states "SOC 2 Certified — We're proud to be SOC 2 certified, the leading industry standard for enterprise-level protection", "All customer data is fully encrypted at rest and we undergo regular vulnerability scanning, penetration tests, and policy reviews", and links to the trust center at https://trust.bikky.com/. machine_readability: readable: false note: >- The Vanta trust report renders client-side. Its GraphQL backend at /graphql rejects anonymous queries with "Missing `signature` or `signedAt`" (HTTP 400), so the certification list, audit reports and subprocessors are not retrievable without a signed session. The SOC 2 certification recorded above is taken from the provider's own homepage copy, not from the trust center DOM. vulnerability_disclosure: published: false note: >- Bikky publishes security PRACTICES (scanning, pen tests) but no channel for third parties to REPORT a vulnerability — no security.txt on any host, no /security or /responsible-disclosure page, no bug bounty program on HackerOne/Bugcrowd/Intigriti, and no security@ address in the privacy policy or terms (the only published address is support@bikky.com). No VulnerabilityDisclosure or Security pointer is wired as a result.