Trust & Security
You are trusting us with your business's financial records. Here is exactly what we do to earn that trust — in plain language, not marketing language.
Accounting software holds the most sensitive information a small business has: who your clients are, what you charge them, what you earn, and what you owe in tax. That data deserves more than a vague security badge and a slogan.
This page describes the specific protections built into iBill — how your data is encrypted, how your books are made tamper-evident, what happens when you want your data back or want it gone, and how to reach us if you ever spot a problem. Everything below describes the platform as it actually runs today.
Layered protections cover your data on the way to us, while it is stored, and every time you sign in.
Every connection between your browser and iBill is encrypted with TLS (HTTPS). There is no unencrypted way to reach the application — invoices, client details, and reports never travel over the open internet in readable form.
Your database records and uploaded files (logos, receipts, attachments) are stored on managed cloud infrastructure that encrypts data at rest, so the underlying storage is protected even below the application layer.
Passwords are never stored — not by us, not anywhere. iBill keeps only a bcrypt hash, a one-way transformation designed specifically for password storage, and enforces password-strength rules when you create one.
Sign-ins use cryptographically signed session tokens. Sessions can be revoked server-side — when a password is reset, previously issued sessions stop working rather than living on.
Repeated failed sign-in attempts trigger automated blocking. If a password-only account signs in from a country it has never used before, iBill asks for a one-time verification code sent to the account email before letting the sign-in complete.
The application ships with modern security headers, CSRF protection on every state-changing request, request rate limiting, and automated blocking of scanners and abusive traffic.
Every financial event — an invoice payment, an expense, a credit note — posts balanced journal entries to a real general ledger. Debits equal credits on every transaction, and automated checks verify it.
Posted journal entries are cryptographically hash-chained: each entry's fingerprint depends on the entries before it. If a posted record were altered after the fact, the chain would no longer validate — so silent edits are detectable, not just forbidden.
Financial actions are recorded to an audit log that is enforced as append-only at the database level — entries cannot be edited or deleted, by anyone, including us.
Automated jobs reconcile the ledger every day — verifying that balances hold, that invoices and payments agree with the general ledger, and that no record has drifted. Anomalies are flagged for human review.
Canadian businesses must keep their books and supporting records for six years. iBill retains your financial records accordingly — including when an account is closed, where retained records are kept in anonymized form.
Our privacy practices are designed to align with PIPEDA, Canada's federal private-sector privacy law. The full detail is in our Privacy Policy.
Your business data is used to run the service for you. We do not sell it, rent it, or share it with third parties for their marketing, and we do not use your records to train third-party AI models.
You can request a complete export of your data at any time through the privacy request page — your records belong to you.
Account deletion is self-serve, from Settings. Personal information is removed on deletion; only records that Canadian tax requirements oblige a business to retain are kept, in anonymized form.
iBill is built on enterprise cloud infrastructure and never handles your clients' card numbers directly.
Online card payments are processed by Stripe, a certified payment processor used by millions of businesses. Card numbers are entered on Stripe-secured payment flows — iBill never sees or stores full card details.
The application runs on Google Cloud with managed PostgreSQL database hosting in North American data centres — the same class of infrastructure that runs banks' and governments' workloads.
Invoices and notifications are sent from an authenticated domain with SPF and DKIM, so the email your client receives is verifiably from iBill and less likely to be spoofed or land in spam.
Errors and anomalies are captured automatically and reviewed daily. Automated integrity checks run on a schedule, and confirmed issues are prioritized ahead of feature work.
If you believe you have found a security problem in iBill, email support@ibill.ca with the details. Reports go to the team that operates the platform, and confirmed issues are prioritized ahead of feature work. Please do not test against other users' data — use your own account.
Free Canadian invoicing and accounting, built on real double-entry bookkeeping and records you can stand behind.
Get Started Free