Security & Trust

Security is one of our top priorities!

Vital and strictly confidential data is exchanged through our platform. At Billabex, we give absolute priority to the security and privacy of your data.

Regulatory Compliance

GDPR Compliance

Billabex is fully GDPR compliant. We manage rights requests (access, deletion, etc.) within 30 days via our DPO.

OWASP Standards

Security best practices (Top 10 OWASP) are integrated from the design phase and throughout every update.

ISO 27001 & SOC 2 Inspired

Our processes are structured according to best practices (ISO/IEC 27001 for management, SOC 2 Type II for controls).

Technical Security

Robust Authentication

Secure access via Argon2id hashing (OWASP compliant). Passwords are never stored in plain text.

Argon2id Algorithm
No plain text storage
Strict password policy

Internal Access Control

MFA (TOTP or SMS code) is mandatory for all high-privilege accounts (Dev, DevOps, Admin).

Mandatory internal MFA
TOTP/SMS authentication
Strictly controlled access

Data Protection

EU Union Hosting

All data is stored on AWS servers in Ireland (EU). No data leaves the EU without an appropriate legal basis.

AES-256 & TLS 1.3 Encryption

Data encrypted at rest via AWS KMS. Communications encrypted in transit via TLS 1.3 with A+ SSL Labs score.

Multi-tenant Architecture

Strict separation by Tenant ID, logical partitioning and automated testing to prevent cross-tenant access.

Availability & Continuity

99.9%
Guaranteed SLA

24/7 availability across 3 redundant AWS availability zones.

< 15 min
RTO Objective

Bussiness Continuity Plan regularly tested and validated.

< 1 min
RPO Objective

Automatic PITR (Point-in-Time Recovery) backups.

Technical Details & Confidentiality

Everything you need to know about the technical management of your data.

Your data is secure. Trust the AI.

Join the finance departments that have chosen security and smart automation.