Skip to content
Security

What we actually built, in plain words

Not a checklist we bought. Here is what protects your data today, and what we're still working toward.

Your data is walled off from every other customer

Every table your business's data lives in is set up so a query for one customer can never return another customer's rows, enforced by the database itself, not just by our application code.

Your account number is encrypted

It's encrypted before it's ever written to disk, and shown with most digits hidden everywhere it's displayed, including to our own staff.

Every file is scanned before anyone opens it

A bill you upload or email in is checked for malware first. If it fails the scan, it's stopped and never reaches a human or an audit.

Every action is logged and the log can't be quietly edited

Who did what, and when, is recorded in a log where each entry is chained to the one before it, so a change made after the fact is detectable.

Sending anything to your utility takes a named person's approval

A recommendation to file a claim, an email, or a call script is drafted first and has to be approved before it goes out. Nothing reaches your utility automatically.

Staff sign in on a separate, harder-to-reach system

Our staff console is a separate application from your account, with its own login and its own extra verification step, so a problem with one system doesn't expose the other.

How we use AI on your bill

The bill itself (the PDF or image) is sent to an AI model to read the charges off it, under a vendor agreement that keeps it out of that vendor's training data. Anywhere else software refers to your account, it sees a masked version, not the real number.

Where we're headed

We're built to the practices a SOC 2 audit checks for. We have not completed a SOC 2 audit yet, and we won't say we have until we do.

Questions about how we handle your data? Send one bill and ask us anything.

Upload one bill
Upload one bill