Billtov handles real financial documents — full names, account numbers, and a precise picture of someone's household finances. Here's how that data is actually protected, and how to request our detailed security documentation.
Each uploaded bill gets its own unique encryption key, generated fresh for that one file. That key is itself protected by a separate master key held in a dedicated, access-controlled cloud security vault (AWS Key Management Service) — the same general approach used by banks and healthcare providers for sensitive documents at rest. The master key never leaves that vault and is never stored alongside the files it protects.
The database itself restricts every user to their own data — even a bug in the application couldn't accidentally return one user's bills in a request scoped to another user, because the restriction lives in the database, not just the app.
Deleting a bill or an account is a genuine, permanent deletion — not a hidden flag that quietly keeps the data around.
When Billtov looks at trends across many users to improve the product, it works only from pseudonymized, de-identified data, and won't generate a comparison unless enough households are represented that no single home's numbers could be singled out.
Infrastructure is hosted in Frankfurt, Germany, under standard European data protection frameworks.
Billtov itself hasn't completed its own independent security audit yet — that's ahead of us, and something we're actively working toward. In the meantime, every piece of infrastructure Billtov runs on has already been independently audited and certified:
Our Information Security, Access Control, Incident Response, and Data Retention policies are available on request. We review every request personally rather than offering instant self-serve access.