Company

Security First: How We Keep Your Payments Safe

An inside look at our security practices and why being non-custodial matters for your business.

Security First: How We Keep Your Payments Safe

When it comes to payments, security isn't optional. Here's how we approach it at billing.io.

Non-Custodial by Design

The most important security decision we made was to be non-custodial. This means:

  • We never hold your funds
  • You maintain full control of your private keys
  • No single point of failure

Our Security Stack

Infrastructure

  • All infrastructure runs on isolated networks
  • Regular penetration testing by third-party firms
  • SOC 2 Type II compliance (in progress)

Smart Contracts

  • Audited by leading security firms
  • Open source for transparency
  • Bug bounty program for responsible disclosure

Application Security

  • End-to-end encryption
  • Hardware key support
  • Multi-factor authentication

Best Practices for Merchants

We also provide guidance to help you maintain security:

  1. Use hardware wallets for withdrawal addresses
  2. Enable webhook signature verification
  3. Regularly rotate API keys
  4. Monitor for unusual activity

Reporting Vulnerabilities

Found something? We have a bug bounty program. Reach out to security@billing.io.