Security
Controls that can’t be skipped.
Biller puts isolation, immutability and data minimization where they are enforced for every request: in the database, at the credential, and at the boundary with your processor and bank.
Isolation
Tenants and environments are separated by the database, not by convention.
- Row-level security is forced on every tenant table; a query outside a tenant context sees nothing
- Composite keys carry tenant and environment, so no row can point into another tenant
- The tenant and environment come from the credential, never from the request
- Test and live data never mix, down to separate gateway accounts
Minimization
The most sensitive data never enters Biller, or is kept apart when it must.
- Card numbers and security codes stay with the processor; Biller keeps its token
- Bank account numbers live in a separate vault, encrypted with AES-256-GCM under their own key
- Billing tables keep only masked digits and a fingerprint
- PAD files are rebuilt on download and never stored
Immutability
What has been agreed, billed or posted can’t be edited, only corrected.
- Triggers refuse changes to finalized invoices, executed contract versions and sent quotes
- Journal entries must balance or they don’t post
- Price economics and subscription segments are effective-dated, never overwritten
- Corrections are new records: credit notes, reversals, amendments
Accountability
Every change can be traced to who made it and the request it came from.
- An append-only audit log records the actor, the subject and the changes
- Every response carries a request id that ties logs, audits and support together
- Downloads that expose bank data are audited like writes
- Quote acceptance records who accepted, through which channel and from which IP address
In the database
What the database refuses.
These rules hold for every write, whichever code path or person attempts it.
- Append-only
- Audit log, journal entries and lines, payment allocations, credit notes, contract executions, policy versions, usage events, statements
- Balanced
- Journal lines for one entry are inserted together and checked by a statement-level trigger
- Frozen once final
- Finalized invoices, sent quote versions, executed contract versions
- Draft-only children
- Invoice, quote and contract lines change only while their document is a draft
- Effective-dated
- Subscription schedule segments and price economics; overlapping segments are rejected
Access
Least privilege, by role and by key.
People sign in to the console with a role; systems use API keys. Both carry an explicit set of permissions, and every endpoint declares the one it needs.
- Owner
- Billing admin
- Collections
- Sales
- Developer
- Support
- Read-only
- API keys and session tokens are stored hashed; a key’s permissions are fixed when it is issued
- An automated check fails the build if any endpoint is added without a permission
- Quote acceptance links are single-use, stored hashed, and expire after 30 days or with the quote, whichever comes first
- Webhook endpoints must use HTTPS and can’t target private, loopback, link-local or metadata addresses
- Webhook secrets rotate without downtime: both sign for 24 hours
Standards
Built on published standards.
Where a standard exists, Biller follows it instead of inventing its own.
- PCI DSS v4.0.1
- Card data collected and stored by the processor; Biller holds tokens
- Payments Canada Rule H1
- PAD mandates, confirmation, pre-notification and cancellation
- CPA Standard 005
- Pre-authorized debit files
- RFC 9457
- Error documents
- CloudEvents 1.0
- Webhook envelopes
- RFC 9562
- UUIDv7 identifiers
- RFC 3339
- Timestamps
- ISO 4217
- Currencies and their minor units
These are design references, not certifications. Compliance for your business is confirmed with your acquirer, your financial institution and your assessors.
Questions about security?
We’ll walk your security and finance teams through the controls on your own scenarios.