Security & Privacy

Your financial data is protected with strong encryption, strict access controls, and continuous monitoring.

Advanced Security Features

Multiple layers of protection for your financial data

Encryption in transit and at rest

Stored data uses managed encryption and network traffic uses TLS. Sensitive biller credentials use customer-specific AWS KMS keys.

  • Managed encryption for data at rest
  • TLS for data in transit
  • Encrypted database storage
  • Secure key management
Encryption in transit and at rest Visualization

Layered Protection

We protect your sensitive financial data with multiple layers of controls — encryption, least-privilege access, and ongoing monitoring.

  • Encryption for data at rest and in transit
  • Least-privilege, role-based access controls
  • Isolated, access-controlled data storage
  • Regular internal security reviews
Layered Protection Visualization

Multi-Factor Authentication

Additional security layers protect your account with multiple authentication methods and verification steps.

  • SMS and email verification
  • Authenticator app support
  • Biometric authentication
  • Hardware security keys
Multi-Factor Authentication Visualization

Consented account access

BillEBox accesses connected accounts only for user-requested workflows. Required biller credentials are encrypted rather than stored in plaintext.

  • Encrypted credential vaulting where required
  • User-authorized account workflows
  • Token-based authentication where supported
  • Automatic session expiration
Consented account access Visualization

Our security practices

The practices we follow to keep your data safe

Encryption in transit and at rest

Your data is encrypted while moving between your device and our systems, and while it is stored.

Least-privilege access

Access to systems and data is limited to what each role needs, and reviewed regularly.

Continuous monitoring

We log and monitor system activity so we can detect and respond to unusual behavior.

Data-protection principles

We follow GDPR data-protection principles — data minimization, purpose limitation, and user control.

Comprehensive Security Measures

Proactive security measures to protect your data

Infrastructure Security

Our infrastructure is built on secure cloud platforms with multiple layers of protection.

  • AWS cloud hosting
  • DDoS protection and mitigation
  • Regular security updates
  • Network segmentation

Monitoring and logging

System activity is logged and monitored to support detection and incident response.

  • Real-time threat detection
  • Automated incident response
  • Security event logging
  • Planned independent security testing

Incident Response

Comprehensive incident response procedures to quickly address any security concerns.

  • Incident response plan
  • Documented escalation paths
  • Formal audits are planned work

Privacy Principles

Your privacy is fundamental to our approach

Data Minimization

We only collect the data necessary to provide our services and never store more than required.

Purpose Limitation

Your data is only used for the specific purposes you've consented to and never shared without permission.

Transparency

Clear and understandable privacy policies with regular updates and user notifications.

User Control

You have full control over your data with easy access, modification, and deletion options.

Ready to experience secure bill management?

Your financial data is protected with managed encryption and access controls