Legal
Security
Last updated: July 2026Billingz handles the financial records of independent businesses. That responsibility shapes how the service is built. This page describes our current practice; it will expand as the product moves from early access to general availability.
1. Infrastructure
- The Billingz application is hosted on Amazon Web Services in the European Union (region eu-central-1, Frankfurt), with network isolation and managed security services.
- Customer Data is hosted in the EU. Cross-border processing by service providers is covered by adequacy decisions or Standard Contractual Clauses (see Subprocessors).
- Customer workspaces are logically separated.
2. Encryption
- Data is encrypted in transit (TLS) and at rest.
- Payments are processed by Stripe. Card details never reach or get stored on Billingz systems.
3. Access control
- Role-based access on the principle of least privilege; administrative access requires multi-factor authentication.
- Administrative and system events are logged and monitored.
- Personnel access is need-to-know and covered by confidentiality undertakings.
4. Continuity
- Regular backups with defined retention and tested restore procedures.
- Vulnerability management with timely application of security patches.
5. Certifications
Billingz is an early-stage company and does not currently hold formal security certifications. We do not claim what we do not hold. Our data protection commitments are set out in the Privacy Policy and the Data Processing Agreement.
6. Reporting a security issue
If you believe you have found a vulnerability in Billingz or billingz.com, write to support@billingz.com with a description, the steps to reproduce, and, if possible, the affected URL or component. Reports go directly to the team that builds the product. We confirm receipt and keep you informed while we investigate. We ask that you do not access other people’s data or disrupt the service while demonstrating an issue.