Security at BillyBox
How we handle your email, invoices, and credentials.
Last reviewed: June 2026
Google-verified for Gmail access
BillyBox passed Google's OAuth security review and an independent CASA Tier 2 assessment. Read-only Gmail scope, AES-256-GCM credential encryption, EU-hosted data.
Independent audit
BillyBox passed the CASA Tier 2 security assessment conducted by TAC Security. The audit covered application security (OWASP ASVS), data handling, and OAuth scope justification. The same assessment underpins our Google OAuth verification.
Visit TAC SecurityEncryption
Email credentials and OAuth refresh tokens are encrypted at rest with AES-256-GCM. All traffic is served over TLS 1.2+. Database and object storage encrypt data at rest by default.
Access control
Each user holds a personal JWT session (30-minute access token, 7-day refresh). Invoices, attachments, and email credentials are scoped to your user row — no shared workspaces, no admin browse access, no analytics on document content.
Hosting & data residency
Application and database run in Railway's EU region. PDF and image attachments are stored on Cloudflare R2 (EU). No data is moved outside the EU during normal operation.
Data handling
Read-only Gmail/Outlook scopes — BillyBox can never send, modify, or delete your email. Only invoice-relevant messages and their attachments are persisted; the rest is discarded after the fetch. You can disconnect any inbox or delete your account at any time.
Reporting a vulnerability
Email security@billybox.app with details. We aim to acknowledge within two business days.