Security Policy

Last updated on Jun 23, 2026

Security Policy

Last Updated: June 23, 2026

1. Our Security Commitment

At We-Bills, the security, confidentiality, and integrity of your data is our highest priority. We employ industry-standard security measures and continuously invest in improving our security posture to protect your financial information and business data.

2. Data Encryption

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. We use strong cipher suites and regularly update our TLS configuration to protect against known vulnerabilities.
  • Encryption at Rest: All stored data, including invoices, financial records, and user credentials, is encrypted using AES-256 encryption standards on our Contabo infrastructure.
  • Database Encryption: Database-level encryption is applied to all sensitive fields, including payment information and authentication tokens.

3. Access Controls and Authentication

  • Role-Based Access Control (RBAC): All system access is governed by role-based permissions, ensuring users can only access data and features necessary for their role.
  • Multi-Factor Authentication (MFA): MFA is enforced for all administrative and support accounts. Customers are strongly encouraged to enable MFA on their accounts.
  • Strong Password Requirements: Minimum password complexity requirements are enforced, including length, character variety, and prohibition of common passwords.
  • Principle of Least Privilege: All We-Bills employees and contractors are granted the minimum access necessary to perform their duties.
  • Session Management: Secure session handling with automatic timeout after periods of inactivity; secure session tokens with rotation.

4. Infrastructure and Network Security

Our infrastructure is hosted on Contabo in Germany (European Union), featuring:

  • SOC 2 Type II Certified Data Centers: Physical facilities with 24/7 security monitoring, biometric access controls, and environmental protections
  • Network Segmentation: Logical separation of production, staging, and development environments
  • Firewalls and Intrusion Detection: Next-generation firewalls and intrusion detection/prevention systems (IDS/IPS) monitoring network traffic
  • DDoS Protection: Automated mitigation of distributed denial-of-service attacks to ensure service availability
  • Regular Vulnerability Scanning: Automated and manual vulnerability assessments of our infrastructure and applications
  • Timely Patching: Critical security patches are applied within 24 hours; routine patches within 7 days

5. Data Backup and Disaster Recovery

  • Automated Daily Backups: All customer data is backed up automatically every 24 hours
  • Encrypted Backup Storage: Backups are encrypted and stored in geographically separate locations within the EU
  • 30-Day Retention: Backup retention period of 30 days with point-in-time recovery capabilities
  • Disaster Recovery Testing: Regular disaster recovery drills to validate backup integrity and recovery procedures
  • Recovery Time Objective (RTO): 4 hours; Recovery Point Objective (RPO): 24 hours

6. Incident Response

We maintain a documented incident response plan with defined roles, procedures, and escalation paths. In the event of a security incident:

  • Immediate Containment: Rapid identification and isolation of affected systems
  • Investigation: Thorough root cause analysis by our security team
  • Notification: Affected customers are notified within 72 hours of confirmed incidents involving their data
  • Remediation: Implementation of corrective measures to prevent recurrence
  • Post-Incident Review: Documentation of lessons learned and process improvements

7. Compliance and Certifications

We-Bills is committed to meeting the following standards:

  • General Data Protection Regulation (GDPR): Full compliance with EU data protection requirements Active
  • PCI DSS: Payment Card Industry Data Security Standard compliance through our payment processors (Stripe); We-Bills does not store raw card data Active
  • SOC 2 Type II: Service Organization Control 2 audit (in progress) In Progress
  • ISO 27001: Information Security Management System certification (planned) Planned

8. Responsible Disclosure and Bug Bounty

We welcome responsible security research and encourage the security community to report vulnerabilities to us. If you discover a security issue:

  • Report it promptly to contact@we-bills.com with subject line "Security Vulnerability Report"
  • Provide sufficient detail to reproduce and validate the issue
  • Allow us reasonable time (90 days) to address the issue before public disclosure
  • Do not exploit the vulnerability beyond what is necessary to demonstrate the issue

We commit to:

  • Acknowledging receipt of your report within 48 hours
  • Investigating and addressing valid reports promptly
  • Not taking legal action against good-faith security researchers
  • Publicly crediting researchers who responsibly disclose significant vulnerabilities (with their permission)

9. User Security Responsibilities

While we take extensive measures to secure our platform, users also play a critical role in protecting their accounts:

  • Strong Passwords: Use unique, complex passwords for your We-Bills account
  • Enable MFA: Activate multi-factor authentication in your account settings
  • Keep Credentials Confidential: Never share your login credentials with others
  • Monitor Account Activity: Regularly review your account activity log for unauthorized access
  • Secure Your Devices: Keep your devices updated and protected with antivirus software
  • Report Suspicious Activity: Contact us immediately at contact@we-bills.com if you notice unusual account behavior

10. Third-Party Security

We carefully vet all third-party service providers (sub-processors) for security compliance. Our key providers include:

  • Contabo GmbH — Cloud infrastructure (Germany, EU)
  • Stripe, Inc. — Payment processing (PCI DSS Level 1 certified)

We require all sub-processors to maintain security standards equivalent to our own and to notify us of any security incidents affecting our data.

11. Changes to This Policy

We may update this Security Policy periodically to reflect changes in our practices, technologies, or legal requirements. Material changes will be posted on this page with a revised "Last Updated" date. We encourage you to review this policy regularly.

12. Contact Us

For security questions, vulnerability reports, or concerns about the security of your data, contact us at:

Email: contact@we-bills.com
Website: https://we-bills.com
Subject Line: "Security Inquiry" or "Vulnerability Report"

© 2026 We-Bills. All rights reserved.