Security & Data Protection Built In from Day One
Your financial data is protected by mandatory tenant isolation, TLS 1.3 encryption, Redis token revocation, and zero raw card storage.
Every table uses PostgreSQL Row Level Security (RLS). Cross-organization queries fail at the database level even if application filters are accidentally omitted.
Logout immediately revokes access tokens via a high-performance Redis denylist, enforcing immediate session termination across all devices.
All network traffic is encrypted using TLS 1.3. Database storage and backups are encrypted at rest using AES-256 keys.
WilBill operates on static payment instructions and manual bank transfers. Raw credit card numbers never touch WilBill servers or databases.
Client portal authentication uses isolated token scopes. Portal users can never access internal organization management routes.
Zero conversational AI agents or LLMs have access to your database. Automation is deterministic and explicitly triggered.
Authorized Sub-processors
Infrastructure providers used to deliver the platform.
| Provider | Purpose | Data Scope |
|---|---|---|
| Cloudinary | File and document storage | Receipts, logos & signed invoice PDFs |
Responsible Disclosure Program
If you discover a potential vulnerability in WilBill, please report it to our security team at security@wilbill.app. We investigate all reports promptly and act within 24 hours.