Security

How we protect your data

BillerAPI handles sensitive financial data. We are transparent about what we implement today and where we are headed.

What we implement today

Credential handling

Supported biller-connection paths use restricted application storage and service access controls. Credential lifecycle and deletion behavior can vary by integration.

Encryption controls

Deployed AWS services provide managed storage-encryption capabilities, and public API endpoints use HTTPS. This is a description of current controls, not a certification or guarantee about every customer integration.

Authentication and access control

The platform uses AWS Cognito for portal identity, API keys for API access, and service-specific AWS permissions. Authorization coverage is tested at defined application boundaries.

Infrastructure isolation

Production services are designed around AWS network and service access controls. Exact deployment boundaries and configurations are reviewed operationally and may change as the platform evolves.

Monitoring and logging

Services emit structured logs and operational health signals. Monitoring and alert coverage varies by service and environment.

Application security

The codebase applies validation, browser security headers, session-cookie controls, and dependency checks at documented boundaries. These controls are continuously reviewed and are not represented as universal certification coverage.

Security roadmap

We are an early-stage company building toward formal certifications. We do not currently hold SOC 2, PCI DSS, ISO 27001, or HIPAA certifications.

InitiativeStatusTarget
SOC 2 Type II auditPlannedPost-funding
Penetration testingPlannedPre-production launch
Bug bounty programPlannedPost-launch
GLBA compliance assessmentEvaluatingTBD

Report a vulnerability

If you discover a security issue, use our contact page and identify the message as a vulnerability report. Reports are triaged based on severity; this page does not promise a specific response or resolution time.