Security & trust

Your data is protected. And you can verify how.

Billabex secures billing data and client communications while clearly separating its own safeguards from the certifications held by its AWS hosting infrastructure.

Information updated April 1, 2026

What is covered by Billabex and what is covered by AWS

Billabex does not currently hold ISO 27001 or SOC 2 certification. These certifications cover the AWS infrastructure used by the service; Billabex safeguards are documented separately below.

  • ISO 27001

    AWS infrastructure

    Certification of AWS’s information security management system.

  • SOC 1, 2, and 3

    AWS infrastructure

    AWS audit reports covering controls including security, availability, and confidentiality.

  • PCI-DSS

    AWS infrastructure

    AWS infrastructure compliance with security requirements for payment data.

  • GDPR and AI Act framework

    Billabex safeguards

    Data minimization, disclosure of AI use, traceability, and human oversight.

  • Collection data hosted in the EU

    Billabex architecture on AWS

    The core infrastructure processing debtor data is hosted in Ireland in the eu-west-1 region.

  • TLS 1.3

    Billabex safeguard

    Communications with the service are encrypted in transit using TLS 1.3.

How Billabex protects your data

Concrete safeguards explained without conflating Billabex controls with our hosting provider’s certifications.

Hosting in the European Union

Collection data entrusted to Billabex is processed on AWS infrastructure located in Ireland. Our public sub-processor list identifies the services used, data categories, locations, and applicable transfer mechanisms.

Primary region
AWS eu-west-1, Ireland
Certified scope
AWS infrastructure: ISO 27001, SOC 1/2/3, and PCI-DSS

Encryption in transit and at rest

Data is protected while it is transmitted and while it is stored. We do not describe this as “end-to-end encryption,” which refers to a different protection model.

In transit
TLS 1.3 protocol
At rest
AWS KMS encryption for databases, files, and emails

Isolation between organizations

Every business request is associated with the relevant organization. This logical separation prevents one client from accessing another client’s data.

Isolation
Organization context injected into each business request
Verification
Automated non-regression tests for data access boundaries

Limited data and controlled access

Billabex limits processing to information required for collection. Team access to production systems is protected by MFA, granted according to least privilege, and logged.

Data processed
Identity, contact details, invoices, and communications needed for collection
Individual rights
Access, rectification, or deletion through our contact form

Service continuity

The asynchronous architecture allows reminders to resume after an interruption. Availability commitments depend on the applicable contract.

Availability
99.9% contractual SLA
Backups
35-day point-in-time recovery for the database

Still have a question? Ask us directly.

Our team answers security, privacy, and compliance questions before you make a decision.