Billerang Logo

Security at Billerang

Your billing data is some of the most sensitive information in your business. We protect it with the same rigor we would apply to our own.

Security Practices

Security is built into every layer of the Billerang platform, from development practices to production operations.

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. API keys and credentials are stored using industry-standard key management systems.

Access Controls

Role-based access control (RBAC) with the principle of least privilege. Multi-factor authentication enforced for all administrative access. Session management with automatic timeouts.

Monitoring & Logging

Continuous security monitoring with real-time alerting. Comprehensive audit logging for all operations. Automated threat detection and anomaly identification.

Vulnerability Management

Regular security assessments and penetration testing. Automated dependency scanning for known vulnerabilities. Responsible disclosure program for external researchers.

Infrastructure Security

Production infrastructure designed for resilience, isolation, and defense in depth.

Kubernetes Orchestration

Production workloads run on hardened Kubernetes clusters with network policies, pod security standards, and automated scaling to ensure availability and isolation.

Tenant Isolation

Multi-tenant architecture with strict data isolation at the database, application, and network layers. Each tenant operates in a logically separated environment.

Network Security

Private networking between services. Ingress filtering and Web Application Firewall (WAF) for all public endpoints. DDoS mitigation at the infrastructure layer.

Compliance Roadmap

Our commitment to meeting the highest standards of data protection and regulatory compliance.

GDPR

Compliant

Full compliance with the EU General Data Protection Regulation. Data processing agreements available for all customers. EU data residency guaranteed.

SOC 2 Type II

Planned

SOC 2 Type II audit planned for 2026. Controls already implemented for security, availability, and confidentiality trust service criteria.

PCI DSS

By design

Billerang never stores cardholder data. Card processing is delegated to PCI-compliant payment service providers, and only PSP tokens and masked references such as the last four digits are kept.

Data Protection

Encryption at rest: All customer data encrypted using AES-256 encryption with managed encryption keys rotated regularly.

Encryption in transit: All communications secured with TLS 1.3. Certificate pinning for internal service communication.

Backup policies: Automated daily backups with point-in-time recovery. Backups encrypted and stored in geographically separate locations within the EU.

Data retention: Customer data retained per contractual terms. Complete data deletion upon request within 30 days of account termination.

Responsible Disclosure

We value the security research community and welcome responsible disclosure of vulnerabilities. If you discover a security issue in the Billerang platform, please report it to our security team.

Please send security vulnerability reports to contact@shareteal.com with the subject line "Security Vulnerability Report". We commit to acknowledging reports within 48 hours and providing regular updates on remediation progress.

Questions About Security?

Our team is available to discuss security practices, compliance requirements, and provide documentation for your vendor review process.

Contact Our Security Team