Trust & security

A clear view of how Billflow handles business data.

Billflow is being built as an accountable operations layer for invoicing and customer administration. This page describes the controls that exist in the product and the standards we apply to new integrations.

Last updated 16 August 2026

Tenant-scoped data access

Authenticated workspace records are protected by tenant ownership checks and database row-level security. New integrations must preserve the same business boundary.

Secrets stay server-side

Service-role, payment and email credentials are kept in secure server configuration rather than shipped to the browser or committed to source control.

AI with controls

AI automation is configurable. Financial actions can require approval, high-risk actions can be blocked, and customer text alone is not treated as payment truth.

Privacy requests are traceable

Workspace owners can export their data and record privacy requests. Privacy exports and requests create a tenant-scoped audit event without copying the personal data into the audit log.

Data ownership and control

Businesses remain responsible for the customer information they choose to put into Billflow. Billflow uses that information to provide the invoicing, payment, collections and configured AI/admin features requested by the business.

Workspace owners can download a machine-readable export from Settings → Privacy & data. Requests concerning access, correction, restriction, deletion, objection or portability can also be recorded there for review.

Payments

Billflow does not need to store raw card details. Card and payment-account processing is handled by the connected payment provider. Billflow stores the payment and invoice status information needed to operate the service.

Automation and AI

Automation is not treated as unrestricted authority. Billflow includes business-level AI controls, approval requirements and escalation paths. A customer saying that an invoice is paid does not, by itself, mark that invoice as paid; payment status is verified against Billflow payment records.

Integrations by design

Every new accounting, CRM or communications integration is expected to follow these rules:

  • request the minimum practical permissions and fields;
  • keep credentials and refresh tokens server-side;
  • scope every synced record to the authorised Billflow business;
  • document what data moves, why it moves and which provider receives it;
  • support disconnection and an appropriate deletion or retention workflow; and
  • review processor terms and international-transfer safeguards before production use.

Incident handling

Billflow maintains an incident-response process covering containment, evidence preservation, risk assessment, customer notification and regulatory assessment. Security or privacy concerns can be reported to hello@billflowinvoicing.com.

Service providers

Billflow relies on specialist providers for hosting/database services, payments and transactional email. See the current subprocessor list and our Data Processing Addendum for the contractual framework we use when Billflow acts as a processor.

No made-up certifications

Billflow does not currently claim its own ISO 27001 or SOC 2 certification. Where a supplier has independent certifications, those belong to that supplier and are not presented as Billflow certifications.

Procurement questions

If your company needs security, privacy or vendor due-diligence information before using Billflow, contact hello@billflowinvoicing.com.