Billing that keeps its own books.
Biller runs quotes, contracts, subscriptions, invoices and collections through one API, on the card processor and bank you already use. Every change is priced before it’s committed, every posting balances, and nothing is rewritten.
Quotes · Contracts · Subscriptions · Invoices · A/R · Payments · Entitlements

One system of record
From signed quote to settled cash.
Each stage is its own record with its own rules, linked by policy, so a change in one place never quietly rewrites another.
- 01
Quote
Versioned, accepted by link
- 02
Contract
Sealed with a checksum at signing
- 03
Subscription
Effective-dated, never edited
- 04
Invoice
Finalized once, corrected by credit note
- 05
Collections
Reminders, fees and holds on a policy
- 06
Payment
Idempotent, reconciled when uncertain
- 07
Settlement
Matched to the deposit, fees posted
- 08
Entitlement
Access that follows the bill
Processor-independent
Subscriptions and invoices stay valid when you change gateways. Processors and banks move the money; Biller keeps the terms, the math and the books.
Immutable by design
Executed contracts, finalized invoices and posted journal lines are locked by the database. Corrections are amendments, credit notes and reversals.
Preview before commit
Plan changes and contract amendments are priced by the same code that commits them, so the preview is the invoice.
Exactly-once effects
Idempotency keys on money commands, one claim per billing period, and a timeout is never mistaken for a decline.
Quotes & contracts
Quotes customers accept with a link. Contracts nobody can quietly edit.
Send a versioned quote with a single-use acceptance link. Acceptance records who decided, when and from where, then drafts the contract. Executing it seals the terms and creates the subscriptions and one-time charges in one transaction.
- Negotiated prices snapshot onto each line, untouched by later catalog changes
- Ramps, one-time charges, renewals and notice terms on the contract
- Amendments preview the exact proration before they execute
- Terminations end billing at local midnight and credit unused time

Subscriptions & invoicing
Change a plan mid-cycle. See the exact invoice first.
Subscriptions are effective-dated schedules, not mutable rows. A change closes one segment and opens the next, and proration is computed to the second in the subscription’s own time zone.
- Flat, per-unit, volume, graduated, package and metered prices
- Calendar billing with month-end anchors and real daylight-saving hours
- Prorations land on the next invoice, invoice now, or not at all
- Finalized invoices are frozen; credit notes and voids post reversing entries

Accounts receivable
Collections that run on schedule and stop the moment an invoice is paid.
Build dunning policies from reminders, late fees, service holds, tasks and autopay retries, timed from each invoice’s due date. Every invoice keeps the policy version it was finalized under.
- Payment plans pause dunning while they’re kept, and resume it if they default
- Late fees with caps, never charged on an invoice made of late fees
- Statements with an opening balance, running balance and aging
- Aging by currency and customer, as of any date

Entitlements & usage
Access that follows the bill.
Products grant features and subscriptions carry the grants. Your application asks one endpoint whether a customer may use something, and the answer already accounts for overrides and collection holds.
- Typed features: switches, limits, allowances, durations
- Overrides with a reason and an effective date, revoked rather than deleted
- Usage events are idempotent by event id; corrections are new events
- Usage summaries aggregate exactly the way invoicing does

Subledger
A subledger that balances, or doesn’t post.
Every invoice, payment, credit, refund and processing fee posts a double-entry journal entry. The database rejects an unbalanced entry and refuses edits to posted lines. Customer balances are derived from postings, never from invoice flags.
- Receivables, revenue, tax payable, cash clearing, customer credit, fees and bad debt
- Voids, returns and write-offs are reversing entries with their own audit trail
- Settlement fees post as they’re reconciled

Payments
Your processor. Your bank. One orchestration layer.
Biller never holds funds. It prepares each attempt, submits it to the gateway and records the normalized outcome, so a network timeout becomes a reconciliation, not a double charge.
Moneris
Payment methods are processor tokens, so card numbers stay out of your systems and ours. Status checks settle attempts whose outcome is unknown.
RBC
Mandates with agreement evidence, Rule H1 confirmation and pre-notification, CPA-005 files, and returns that reopen invoices and reschedule collections.
Settlements
Import a processor’s settlement once. Each item is matched by reference, fees post to the ledger, and the expected net is checked against the deposit.
Developers
An API designed for the retry.
Every endpoint the console uses is public. Retries are safe, errors are typed, and webhooks arrive as signed CloudEvents.
- Idempotency-Keyon every money command, replayed with Idempotent-Replayed: true
- RFC 9457problem details with stable error codes
- Cursor paginationwith ETags and If-Match on versioned resources
- Test and liveenvironments with separate keys and data
curl "$BILLER_API/subscriptions/$SUBSCRIPTION/preview-change" \
-H "Authorization: Bearer $BILLER_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"changes": [{
"subscription_item_id": "01a10b01-070f-7008-aa36-e1d6e866f415",
"quantity": "52"
}],
"proration_behavior": "create_prorations"
}'{
"data": {
"currency": "CAD",
"effective_at": "2026-10-05T07:57:43Z",
"credits_minor": -6214,
"charges_minor": 7025,
"tax_minor": 105,
"amount_on_next_invoice_minor": 916,
"next_recurring_total_minor": 133905,
"lines": [
{
"description": "Unused time on Fleet Telematics — Per vehicle",
"quantity": "46",
"total_minor": -7022,
"calculation_trace": {
"fraction": "0.075052854938271605",
"proration_policy": "proration/v1"
}
},
…
]
}
}curl "$BILLER_API/subscriptions/$SUBSCRIPTION/changes" \
-H "Authorization: Bearer $BILLER_API_KEY" \
-H "Idempotency-Key: 6f1d2c1e-3b0a-4f7e-9d61-0c8a5e2b7f43" \
-H "Content-Type: application/json" \
-d @change.jsonHTTP/1.1 201 Created
Idempotent-Replayed: true
# The same key with the same body returns the stored
# response. The change is applied exactly once.curl "$BILLER_API/entitlements/check" \
-H "Authorization: Bearer $BILLER_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"customer_id": "01a10b01-062f-721a-a7e8-f2630010fa44",
"feature_key": "max_vehicles",
"quantity": "64"
}'{
"data": {
"allowed": false,
"reason": "limit_exceeded",
"feature_key": "max_vehicles",
"value_type": "quantity",
"value": "60"
}
}Security
Built so the wrong thing can’t happen.
Controls live where they can’t be skipped: in the database, at the token, and at the boundary with your processor.
Isolation in the database
Row-level security is forced on every tenant table, and composite keys stop a row from ever pointing at another tenant’s data.
No card numbers, anywhere
Payment methods are processor tokens. Card numbers and security codes never reach Biller.
Bank details in a vault
Account numbers for pre-authorized debit live in a separate encrypted vault. Files that contain them are rebuilt on download, never stored.
Append-only records
Triggers lock finalized invoices, executed contracts and posted journal lines. A correction is always a new record.
A complete audit trail
Every change made through the API or the console records who made it, what changed and the request it came from.
Signed, fenced webhooks
HMAC-SHA256 signatures with timestamps and overlap during secret rotation. Endpoints can’t target private or metadata addresses.
Questions
The short answers.
Something else? Ask us directly.
Does Biller hold or move money?
No. Your card processor and bank move funds and hold payment credentials. Biller owns the commercial terms, the billing math, invoices, the receivables subledger and the orchestration around each payment.
Can we keep our current processor?
Gateways are adapters behind one interface. Biller ships with Moneris for cards, RBC for pre-authorized debit and a sandbox for testing. Subscriptions and invoices don’t change when a gateway does, although processor tokens usually have to be collected again.
What happens when a payment request times out?
The attempt is recorded as unknown and reconciled by asking the gateway about the original reference. It is never retried blindly, and every attempt carries its own idempotency reference, so a resubmission can’t charge twice.
Can an invoice be edited after it’s finalized?
No, by design. Issue a credit note, void it with a reversing entry, or write it off. Each correction posts its own journal entry and audit record.
Is there a test environment?
Every account has test and live environments with separate API keys, data and gateway accounts. The console always shows which one you’re in.
How are Canadian PAD rules handled?
Mandates store the agreement evidence and are checked before every debit: confirmation lead time, pre-notification for variable amounts, and cancellation that blocks future debits at once. Lead times and transaction codes are configurable to match your financial institution.
See your billing on Biller.
Walk through your contracts, invoices and payment rails with us, or start with the API.
Test and live environments from day one