Trust

Security & DPA

How BillFi protects Customer and subscriber data, and how the shared responsibility between us and our Customers is drawn.

Effective January 1, 2026

This page is maintained by BillFi to answer common questions about how BillFi operates. It is app-owner editable content, not an independent certification or legal advice. Where you need something formal, contact security@billfi.net.

1. Shared responsibility

Security in BillFi is a partnership between our platform and your team.

  • BillFi is responsible for the security of the platform itself — infrastructure hardening, encryption, access controls to our systems, patching, monitoring and incident response.
  • You are responsible for how you configure BillFi — user roles you grant, 2FA enforcement, password hygiene, subscriber data you upload, and how you handle lawful requests from your regulators.
  • Your subscribers are responsible for the credentials they use to sign in to their portal.

2. Platform controls

  • Data encrypted in transit using TLS 1.2 or higher, and at rest using AES-256.
  • Role-based access control across the admin app, with per-action audit logs.
  • Two-factor authentication supported for admin accounts, required for BillFi staff with production access.
  • Least-privilege access to production systems, reviewed quarterly.
  • Tenant isolation — each Customer's data is scoped by tenant ID at every layer of the stack.
  • Continuous vulnerability scanning of dependencies and container images.
  • Automated backups encrypted at rest, cycled on a 35-day rolling schedule.

These describe enabled platform controls. This page is not an independent certification.

3. Hosting & data locality

BillFi runs on major cloud providers with SOC 2 and ISO 27001 certified data centres. Production regions include Singapore, Frankfurt and Nairobi, with disaster-recovery snapshots replicated across regions.

Enterprise Customers may request a specific region for data-locality reasons (for example, in-country hosting to meet a national regulator's guidance).

4. Sub-processors

BillFi uses vetted sub-processors for hosting, transactional email, SMS delivery, error monitoring, analytics and payment gateways selected by the Customer. Categories include:

  • Cloud infrastructure (hosting, storage, networking).
  • Transactional email & SMS delivery providers.
  • Error and performance monitoring tools.
  • Payment gateways enabled per-Customer (Stripe, Flutterwave, Paystack, bKash, Nagad, M-Pesa, etc.).

A current sub-processor list is provided with the signed DPA. Request it via security@billfi.net.

5. Network & authentication data

RADIUS authentication, session accounting and NAT logs are processed on the Customer's behalf. Retention is Customer-configurable and defaults to values commonly used in the Customer's regulatory environment. Contents of these logs are never used for any purpose other than delivering the service to that Customer.

6. Payment data

BillFi does not store full card PANs. Cards are tokenised at the gateway (Stripe, Flutterwave, SSLCommerz and similar). Mobile-money transactions are stored as gateway references, amounts, currencies and timestamps — no wallet PIN or password is ever handled by BillFi.

7. Incident response

We run 24/7 on-call rotation for production incidents. Security incidents follow a documented playbook: contain, investigate, notify.

Customers affected by a confirmed data-security incident are notified within 72 hours of confirmation, with the information required to meet their own regulator obligations.

8. Reporting a vulnerability

If you believe you've found a security issue in BillFi, please report it privately to security@billfi.net. Include steps to reproduce and — where possible — a proof-of-concept.

We acknowledge reports within 2 business days, keep you updated on remediation, and credit researchers who report responsibly (if desired).

9. Data Processing Addendum (DPA)

Where BillFi processes personal data on behalf of a Customer, a Data Processing Addendum governs that processing. The DPA covers:

  • Roles (controller / processor) and subject-matter.
  • Types of personal data and categories of data subjects.
  • Duration, retention and deletion.
  • Sub-processor list, plus notice for adding new sub-processors.
  • Standard Contractual Clauses for international transfers where applicable.
  • Security measures, audit rights and breach-notification timelines.

Request a signed DPA at security@billfi.net. Enterprise plans include one by default.

10. Compliance posture

BillFi is built to help our Customers meet obligations under frameworks such as GDPR, and to align with regional regulator expectations (for example, NAT-log retention for ISP licences, and VAT-formatted invoicing).

This page describes the controls and practices we operate. Independent audit reports and certifications, where available, are shared under NDA on request; the presence of a certificate is confirmed via the issuing body.