Skip to content
Appearance

Security starts with deliberate choices

Financial information is sensitive. We limit what we need, protect access and remain clear about what security can and cannot guarantee.

Last updated

Our approach in five principles

Security is a continuous process, not a one-off badge.

  • Less data, less risk

    We design for data minimisation and do not ask you to connect a bank account.

  • Protection in transit and at rest

    We use established encryption practices and protect systems and data from unauthorised access.

  • Need-to-know access

    Permissions are limited, reviewed and withdrawn when no longer needed.

  • Secure development and releases

    Changes pass technical checks, tests and a controlled release process.

  • Prepared for incidents

    We investigate signals, contain impact, recover carefully and notify where required.

What BillMeister deliberately does not request

The app does not need access to your bank account and does not process payments. You choose which bills and reminders to record. This keeps the service understandable and reduces the sensitive information it needs.

We do not sell personal data or use advertising trackers to build profiles across different websites.

Technical and organisational safeguards

  • Encrypted connections for traffic between your device and our services.
  • Server-side authorisation and separate roles for users, administration and systems.
  • Restricted access to production data and accounts and sessions that can be revoked.
  • Secure configuration, security headers and management of sensitive keys outside public source code.
  • Checks for dependencies, code quality, types, tests and release readiness.
  • Logging, monitoring, backups and recovery procedures appropriate to the service and its risks.
  • Assessment and limitation of providers that process data on our behalf.

We reassess safeguards as features, threats and technology change. We do not publish operational detail that could make abuse easier.

Detection, response and recovery

For a potential incident, we first establish the facts, restrict access or impact and restore secure operation. We then assess the cause, consequences and improvements.

Where personal data may be affected, we follow our data-breach process and notify affected people and the Dutch Data Protection Authority when risk and law require it.

Responsible disclosure

If you believe you found a vulnerability, send a clear description, reproduction steps and potential impact. Do not access other people’s data or publish the finding before we have had a reasonable opportunity to investigate.

We acknowledge reports, prioritise their review and keep you informed where possible. We treat good-faith reports that follow these principles carefully and respectfully.

Reports and further information

BillMeister

Report a security issue

Describe what you found, how we can reproduce it and the possible impact. Please do not exploit the issue further.

Maximum 5 MB. JPG, PNG, WebP or a UTF-8 text file only.