Security and trust

Your data is safe with us

Financial data is sensitive. Here's exactly how Billvy protects yours.

Passwords
bcrypt hashed
Transport
HTTPS / TLS
Sessions
httpOnly cookies

How we protect your account

Password hashing — passwords are never stored in plain text. We use bcrypt with a cost factor of 10.
Secure session cookies — authentication tokens are stored in httpOnly, SameSite cookies, completely inaccessible to JavaScript and resistant to XSS.
JWT tokens — session tokens are signed with a secret key and expire after 7 days.
HTTPS everywhere — all traffic between your browser and our servers is encrypted using TLS.
Password resets — resets happen through a single-use link emailed to the address on the account. The link expires after 60 minutes, and requesting one never reveals whether an account exists.
Per-user data isolation — every endpoint that touches your records requires a valid session, and each query is scoped to your account. You can only ever access your own data.
Two-factor authentication — optional, standards-based (works with Google Authenticator, Authy, 1Password, and similar apps). Turn it on from Settings → Security. Backup codes are shown once at setup — save them somewhere safe.

Your data

Your invoices, expenses, clients, and projects belong entirely to you. We do not sell, share, or use your financial data for advertising or any purpose other than running the service.

You can export a full copy of your data at any time from Settings → Security → Export your data. You can also delete your account from Settings → Security → Delete account: your invoices, expenses, clients, projects and login are removed from the live database immediately and permanently. Encrypted infrastructure backups roll off within 30 days.

Ask Billvy and your data

The "Ask Billvy" analyst and your Billvy Brief are powered by Anthropic's Claude API. A summary of your invoices, expenses, and clients is sent to Anthropic only at the moment you ask a question or open your Brief — never in the background, and never to any other AI provider. Anthropic does not use API data like this to train its models.

Billvy itself never queries your database with an AI model or lets it change your records — every number is calculated by Billvy first, and the model only explains numbers that already exist. See the Privacy Policy for the full detail.

What we don't do

We do not sell your data to advertisers or third partiesNever
We do not use third-party tracking cookiesNever
We do not store your plain-text passwordNever
We do not expose admin endpoints without authenticationNever

Report a vulnerability

If you discover a security issue, please report it responsibly via our contact page with the subject "Security report". We take all reports seriously and respond within 48 hours.