Advanced security for your financial operations

Reduce risk, combat fraud, and keep your data secure with BILL.
Get Started
Header image
Dashboard mockup

Designed with your privacy and security in mind

Multi-layered security

Multiple layers of powerful technology are integrated into the platform to combat payment fraud, network security breaches, and unauthorized account access, so we can protect sensitive customer data.

AICPA SOC 2 compliance

BILL adheres to the SOC 1 and SOC 2 compliance standards of the American Institute of CPAs (AICPA), undergoing an annual SOC 1 and SOC 2 Type II Audit for BILL Accounts Payable, BILL Accounts Receivable, and BILL Spend & Expense.

Get Started

Protections for BILL Accounts Payable and BILL Accounts Receivable 

Reduce your payment risk

Pay and get paid through our digital network

Keep bank account information private by making digital payments through a secure network of more than 8 million on BILL.

Enjoy enhanced security for check payments

BILL sends checks through a clearing account, so your own account remains hidden, and applies the kind of advanced payment protections that most banks charge for, like Positive Pay.

No third-party issuers

Unlike other AP platforms that use third-party services to issue payments, BILL Accounts Payable and Accounts Receivable keeps your payment processing in-house. That lets you mask your banking information while giving you more control over your payments and better visibility into their status.

HIPAA compliance

For healthcare organizations that need to maintain compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), BILL Accounts Payable and BILL Accounts Receivable provide safeguards for electronic protected health information (ePHI).

Secure data centers

Secure data center facilities with full redundancy in more than one physical location provide back-up protection against malicious attacks.

Advanced protection against data breaches

BILL Accounts Payable and BILL Accounts Receivable ensures customer data is protected at rest with encryption, while Transport Layer Security (TLS) provides bank-level protection during transfer.

Get Started
Dashboard mockup

 How we keep BILL Spend & Expense secure

Dashboard mockup

Designed with your privacy and security in mind

Multi-factor authentication

For company administrators with access to sensitive company information and controls, we require multi-factor authentication (MFA).

PCI compliance

BILL Spend & Expense is PCI compliant. That means we meet the Payment Card Industry Data Security Standard (PCI DSS) for organizations that handle branded credit cards.

Face and touch logins

The BILL Spend & Expense mobile app uses the latest security features, including Android fingerprint scanning and Apple Touch or Face ID.

Fraud protection

BILL Spend & Expense uses an advanced third-party platform that monitors all transactions in real-time and helps to prevents complex fraud incidents with speed and accuracy to protect your business.

Secure data centers

BILL's production environment is located in Amazon Web Services (AWS) across 3 physically separate availability zones in the US-West-2 region, protecting services from loss of connectivity, power issues or other location specific outages.

Full data backups are being saved continuously to the US-East-2 environment.

Get Started

Need more details?

Download Security Spec Sheet
Belay logo
“We pay over 1,000 contractors from a single platform—on time, every month—keeping our banking information encrypted while syncing those payments with our accounting software, QuickBooks Online. We couldn't do that without BILL.”
— Elizabeth Reid, Corporate Compliance Accountant, BELAY
Dashboard mockup

Frequently asked questions

Responsible Disclosure Program

We take security seriously at BILL and are deeply appreciative of the role that security researchers play in improving the security posture of our product and platform.

We partner with HackerOne to facilitate responsible disclosure of any security issues impacting BILL services. If you believe you have discovered a security vulnerability that you would like to report, please submit it to our Vulnerability Disclosure Program here.

Report suspicious activity

Notice something fishy with your BILL account, or believe your information has been compromised?

Let us know >

Report phishing scams

Receive a suspicious email from someone claiming to represent BILL?

Don't reply to it

Don't click on any links

Don't open any attachments

Forward the email immediately to: phishreport@hq.bill.com
Dashboard mockup

See where financial automation can take your business

Join the millions who pay or get paid with BILL.

Get Started