Tenant-scoped data access
Authenticated workspace records are protected by tenant ownership checks and database row-level security. New integrations must preserve the same business boundary.
Billflow is being built as an accountable operations layer for invoicing and customer administration. This page describes the controls that exist in the product and the standards we apply to new integrations.
Last updated 16 August 2026
Authenticated workspace records are protected by tenant ownership checks and database row-level security. New integrations must preserve the same business boundary.
Service-role, payment and email credentials are kept in secure server configuration rather than shipped to the browser or committed to source control.
AI automation is configurable. Financial actions can require approval, high-risk actions can be blocked, and customer text alone is not treated as payment truth.
Workspace owners can export their data and record privacy requests. Privacy exports and requests create a tenant-scoped audit event without copying the personal data into the audit log.
Businesses remain responsible for the customer information they choose to put into Billflow. Billflow uses that information to provide the invoicing, payment, collections and configured AI/admin features requested by the business.
Workspace owners can download a machine-readable export from Settings → Privacy & data. Requests concerning access, correction, restriction, deletion, objection or portability can also be recorded there for review.
Billflow does not need to store raw card details. Card and payment-account processing is handled by the connected payment provider. Billflow stores the payment and invoice status information needed to operate the service.
Automation is not treated as unrestricted authority. Billflow includes business-level AI controls, approval requirements and escalation paths. A customer saying that an invoice is paid does not, by itself, mark that invoice as paid; payment status is verified against Billflow payment records.
Every new accounting, CRM or communications integration is expected to follow these rules:
Billflow maintains an incident-response process covering containment, evidence preservation, risk assessment, customer notification and regulatory assessment. Security or privacy concerns can be reported to hello@billflowinvoicing.com.
Billflow relies on specialist providers for hosting/database services, payments and transactional email. See the current subprocessor list and our Data Processing Addendum for the contractual framework we use when Billflow acts as a processor.
Billflow does not currently claim its own ISO 27001 or SOC 2 certification. Where a supplier has independent certifications, those belong to that supplier and are not presented as Billflow certifications.
If your company needs security, privacy or vendor due-diligence information before using Billflow, contact hello@billflowinvoicing.com.