Bank-Grade Security Architecture

Security & Data Protection Built In from Day One

Your financial data is protected by mandatory tenant isolation, TLS 1.3 encryption, Redis token revocation, and zero raw card storage.

Database RLS Isolation

Every table uses PostgreSQL Row Level Security (RLS). Cross-organization queries fail at the database level even if application filters are accidentally omitted.

JWT Revocation Denylist

Logout immediately revokes access tokens via a high-performance Redis denylist, enforcing immediate session termination across all devices.

Encryption In Transit & At Rest

All network traffic is encrypted using TLS 1.3. Database storage and backups are encrypted at rest using AES-256 keys.

Zero Card Storage

WilBill operates on static payment instructions and manual bank transfers. Raw credit card numbers never touch WilBill servers or databases.

Isolated Client Portal Tokens

Client portal authentication uses isolated token scopes. Portal users can never access internal organization management routes.

No Autonomous AI Execution

Zero conversational AI agents or LLMs have access to your database. Automation is deterministic and explicitly triggered.

Authorized Sub-processors

Infrastructure providers used to deliver the platform.

ProviderPurposeData Scope
CloudinaryFile and document storageReceipts, logos & signed invoice PDFs

Responsible Disclosure Program

If you discover a potential vulnerability in WilBill, please report it to our security team at security@wilbill.app. We investigate all reports promptly and act within 24 hours.

Security FAQs