Skip to content

Security

Invoice evidence is sensitive. Security claims should be evidence-based too.

Billproof is in early access. This page distinguishes the public knowledge base from the invoice-ingestion product and states current boundaries without implying certifications or controls that do not exist yet.

Public directory requires no accountNo password-based portal scrapingDirect connections labelled per vendor

Public website

The vendor knowledge base does not require invoice access.

Vendor records, retrieval guides, and the public JSON registry can be used without an account. They contain vendor documentation and Billproof capability statements, not customer invoice data.

Account access

No stored vendor passwords and no credential-based scraping.

  • Billproof does not ask users to share a vendor-portal password.
  • Browser-assisted retrieval recipes run in the user's own authenticated session.
  • Direct integrations must use approved authorization or documented vendor APIs.
  • Every vendor page separates a working connection from a manual retrieval guide.

Invoice evidence

Original documents remain the source of truth.

The early-access product is designed to retain the submitted invoice alongside parsed fields, its source, and retrieval time. Extraction is assistive: the original document remains available for review when a field is ambiguous or incorrect.

Current posture

Controls and limitations

  • Website traffic is encrypted in transit with HTTPS.
  • Application authorization is scoped to the signed-in organization.
  • Sensitive service credentials are kept out of public website code.
  • Billproof is not currently SOC 2 or ISO 27001 certified.
  • No independent penetration-test claim is made at this stage.

Responsible disclosure

Report a suspected security issue privately.

Include the affected URL, a clear description, and safe reproduction steps. Do not send live credentials, unredacted invoices, or customer data in an initial report.