Skip to content
Independently verified · Quarterly re-audit
EU VETTED

HiBob

VERIFIED
HR & people · United Kingdom
Founded 2015 · hibob.com ↗

Israeli-founded modern HRIS for mid-market (Tel Aviv + London); 5,000+ customers, heavy US VC, mostly listed for completeness.

Why this score?

HiBob is Israeli-headquartered (Tel Aviv) with London as a major secondary office and offices in NYC, Amsterdam, Berlin, Lisbon, Sydney, Zagreb — country_iso set to GB reflects EU-buyer-facing brand but ownership_signal is eu_hq_us_funded due to Israeli HQ + heavy US VC funding (General Atlantic, Bain Capital Ventures, Insight Partners, Battery Ventures); CLOUD Act exposure material; score 2/5 reflects that this is the weakest 'EU' HR pick in the catalogue from a sovereignty perspective.

SCORE
2.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About HiBob

**HiBob** (the "bob" platform) was founded in **Tel Aviv** in 2015 and operates a significant London office, with additional presence in New York, Amsterdam, Berlin, Lisbon, Sydney, and Zagreb. Targets mid-market (50-2,000 employees) with a modern HRIS UX. Compliance: **ISO 27001 + SOC 2** certified. But the sovereignty / procurement story is weak: **Israeli HQ + heavy US VC funding** (General Atlantic, Bain Capital Ventures, Insight Partners, Battery Ventures) means HiBob is the least "European" entry in this HR set. Listed for completeness and to flag the misperception that "London office" implies "European company" — for compliance-driven EU procurement HiBob fits the alternative-to-BambooHR slot but with material caveats.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
SOC 2
ACTIVE
Informational · US framework
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
Custom pricing

Contact vendor for tier or volume pricing.

View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives in this category