Skip to content
Biller

Security

Controls that can’t be skipped.

Biller puts isolation, immutability and data minimization where they are enforced for every request: in the database, at the credential, and at the boundary with your processor and bank.

Isolation

Tenants and environments are separated by the database, not by convention.

  • Row-level security is forced on every tenant table; a query outside a tenant context sees nothing
  • Composite keys carry tenant and environment, so no row can point into another tenant
  • The tenant and environment come from the credential, never from the request
  • Test and live data never mix, down to separate gateway accounts

Minimization

The most sensitive data never enters Biller, or is kept apart when it must.

  • Card numbers and security codes stay with the processor; Biller keeps its token
  • Bank account numbers live in a separate vault, encrypted with AES-256-GCM under their own key
  • Billing tables keep only masked digits and a fingerprint
  • PAD files are rebuilt on download and never stored

Immutability

What has been agreed, billed or posted can’t be edited, only corrected.

  • Triggers refuse changes to finalized invoices, executed contract versions and sent quotes
  • Journal entries must balance or they don’t post
  • Price economics and subscription segments are effective-dated, never overwritten
  • Corrections are new records: credit notes, reversals, amendments

Accountability

Every change can be traced to who made it and the request it came from.

  • An append-only audit log records the actor, the subject and the changes
  • Every response carries a request id that ties logs, audits and support together
  • Downloads that expose bank data are audited like writes
  • Quote acceptance records who accepted, through which channel and from which IP address

In the database

What the database refuses.

These rules hold for every write, whichever code path or person attempts it.

Append-only
Audit log, journal entries and lines, payment allocations, credit notes, contract executions, policy versions, usage events, statements
Balanced
Journal lines for one entry are inserted together and checked by a statement-level trigger
Frozen once final
Finalized invoices, sent quote versions, executed contract versions
Draft-only children
Invoice, quote and contract lines change only while their document is a draft
Effective-dated
Subscription schedule segments and price economics; overlapping segments are rejected

Access

Least privilege, by role and by key.

People sign in to the console with a role; systems use API keys. Both carry an explicit set of permissions, and every endpoint declares the one it needs.

  • Owner
  • Billing admin
  • Collections
  • Sales
  • Developer
  • Support
  • Read-only
  • API keys and session tokens are stored hashed; a key’s permissions are fixed when it is issued
  • An automated check fails the build if any endpoint is added without a permission
  • Quote acceptance links are single-use, stored hashed, and expire after 30 days or with the quote, whichever comes first
  • Webhook endpoints must use HTTPS and can’t target private, loopback, link-local or metadata addresses
  • Webhook secrets rotate without downtime: both sign for 24 hours

Standards

Built on published standards.

Where a standard exists, Biller follows it instead of inventing its own.

PCI DSS v4.0.1
Card data collected and stored by the processor; Biller holds tokens
Payments Canada Rule H1
PAD mandates, confirmation, pre-notification and cancellation
CPA Standard 005
Pre-authorized debit files
RFC 9457
Error documents
CloudEvents 1.0
Webhook envelopes
RFC 9562
UUIDv7 identifiers
RFC 3339
Timestamps
ISO 4217
Currencies and their minor units

These are design references, not certifications. Compliance for your business is confirmed with your acquirer, your financial institution and your assessors.

Questions about security?

We’ll walk your security and finance teams through the controls on your own scenarios.