Payments
Payments on the rails you already have.
Biller orchestrates your card processor and your bank without holding funds or card numbers. Every attempt is prepared, submitted and recorded in separate steps, so an uncertain outcome is reconciled instead of retried.
Orchestration
Three steps, so nothing charges twice.
No network call ever happens inside a database transaction, and every attempt carries its own idempotency reference to the gateway.
- 1Commit
Prepare
The payment and its attempt are saved with a unique reference before anything leaves Biller.
- 2Network
Submit
The gateway is called outside any transaction, with that reference, so a resubmission is recognized rather than charged again.
- 3Commit
Record
The gateway’s answer is normalized and saved. A terminal attempt is never changed afterwards.
Succeeded
Cash is applied to the target invoices, oldest first, and the rest becomes customer credit. Ledger entries post and the invoices’ remaining collection steps are canceled.
Failed
The decline is recorded with the gateway’s reason. The invoice stays open, and its collection policy decides what happens next.
Unknown
A timeout or dropped connection is not a decline. The attempt is marked unknown and reconciled by asking the gateway about the original reference, never by charging again.
Cards
Moneris, without the card numbers.
Cards are collected by the processor and stored in its vault. Biller keeps the token it gets back, so card numbers and security codes never touch your systems or ours.
- Stored cards as Moneris Vault keys, charged for subscriptions, invoices and payment plan installments
- Status checks settle attempts whose outcome is unknown
- Refunds run through the gateway and can reopen the invoices they reverse
- A sandbox gateway with test tokens for approvals, declines and timeouts in the test environment
- Gateways are adapters behind one interface; subscriptions and invoices don’t change when a gateway does
Pre-authorized debit
Canadian bank debits, by the rules.
Pre-authorized debits through RBC under Payments Canada Rule H1. Mandates carry their evidence, every debit is checked before it is filed, and returns unwind cleanly.
- Mandates record the signer, the method, the agreement version and a SHA-256 of its text
- The earliest compliant debit date respects the confirmation lead time and, for variable amounts, pre-notification
- Canceling a mandate blocks its future debits at once
- Account numbers live in a separate encrypted vault; the billing database keeps the last four digits and a fingerprint
- 1Mandate
Agreement and confirmation
The mandate is stored with its evidence and waits for confirmation to be delivered, unless the payor waived it.
- 2Schedule
Due debits are checked
Each debit is scheduled for the earliest compliant date. Variable amounts send a pre-notice with the amount, date and mandate reference.
- 3CPA-005
One file per currency
Due debits are batched into a CPA-005 file. It is rebuilt from the vault on download, checked against its checksum, and never stored.
- 4Settle
Settled or returned
Debits with no return settle after the bank’s lag. A return by reason code (901 NSF, 905 account closed) fails or reverses the debit and reopens the invoice.

Every download is on the record.
A PAD file holds account numbers, so it exists only while it is being downloaded. Each download is audited with who took it and when, and a file that no longer matches what was generated is refused.
Lead times and transaction codes are configurable to match your financial institution’s requirements.
Reconciliation
Every deposit, explained.
Import a processor’s settlement once. Biller matches each item to the payment or refund it belongs to, posts the fees, and checks the expected net against what actually landed.
- Matched charges become settled; fees post to processing fees
- Unmatched items, amount and status mismatches and chargebacks are flagged as exceptions
- Exceptions never rewrite a payment: a person decides
- Refunds and chargebacks reconcile whichever sign the processor reports them with

Biller is billing software, not a payment processor, acquirer or money transmitter. Your processor and bank move funds and hold credentials; Biller keeps the terms, the math, the ledger and the orchestration around them.
How data is protectedSee your billing on Biller.
Walk through your contracts, invoices and payment rails with us, or start with the API.