Your billing data is some of the most sensitive information in your business. We protect it with the same rigor we would apply to our own.
Security is built into every layer of the Billerang platform, from development practices to production operations.
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. API keys and credentials are stored using industry-standard key management systems.
Role-based access control (RBAC) with the principle of least privilege. Multi-factor authentication enforced for all administrative access. Session management with automatic timeouts.
Continuous security monitoring with real-time alerting. Comprehensive audit logging for all operations. Automated threat detection and anomaly identification.
Regular security assessments and penetration testing. Automated dependency scanning for known vulnerabilities. Responsible disclosure program for external researchers.
Production infrastructure designed for resilience, isolation, and defense in depth.
Production workloads run on hardened Kubernetes clusters with network policies, pod security standards, and automated scaling to ensure availability and isolation.
Multi-tenant architecture with strict data isolation at the database, application, and network layers. Each tenant operates in a logically separated environment.
Private networking between services. Ingress filtering and Web Application Firewall (WAF) for all public endpoints. DDoS mitigation at the infrastructure layer.
Our commitment to meeting the highest standards of data protection and regulatory compliance.
Full compliance with the EU General Data Protection Regulation. Data processing agreements available for all customers. EU data residency guaranteed.
SOC 2 Type II audit planned for 2026. Controls already implemented for security, availability, and confidentiality trust service criteria.
Billerang never stores cardholder data. Card processing is delegated to PCI-compliant payment service providers, and only PSP tokens and masked references such as the last four digits are kept.
Encryption at rest: All customer data encrypted using AES-256 encryption with managed encryption keys rotated regularly.
Encryption in transit: All communications secured with TLS 1.3. Certificate pinning for internal service communication.
Backup policies: Automated daily backups with point-in-time recovery. Backups encrypted and stored in geographically separate locations within the EU.
Data retention: Customer data retained per contractual terms. Complete data deletion upon request within 30 days of account termination.
We value the security research community and welcome responsible disclosure of vulnerabilities. If you discover a security issue in the Billerang platform, please report it to our security team.
Please send security vulnerability reports to contact@shareteal.com with the subject line "Security Vulnerability Report". We commit to acknowledging reports within 48 hours and providing regular updates on remediation progress.
Our team is available to discuss security practices, compliance requirements, and provide documentation for your vendor review process.
Contact Our Security Team