Security starts with deliberate choices
Financial information is sensitive. We limit what we need, protect access and remain clear about what security can and cannot guarantee.
Last updated
Our approach in five principles
Security is a continuous process, not a one-off badge.
Less data, less risk
We design for data minimisation and do not ask you to connect a bank account.
Protection in transit and at rest
We use established encryption practices and protect systems and data from unauthorised access.
Need-to-know access
Permissions are limited, reviewed and withdrawn when no longer needed.
Secure development and releases
Changes pass technical checks, tests and a controlled release process.
Prepared for incidents
We investigate signals, contain impact, recover carefully and notify where required.
What BillMeister deliberately does not request
The app does not need access to your bank account and does not process payments. You choose which bills and reminders to record. This keeps the service understandable and reduces the sensitive information it needs.
We do not sell personal data or use advertising trackers to build profiles across different websites.
Technical and organisational safeguards
- Encrypted connections for traffic between your device and our services.
- Server-side authorisation and separate roles for users, administration and systems.
- Restricted access to production data and accounts and sessions that can be revoked.
- Secure configuration, security headers and management of sensitive keys outside public source code.
- Checks for dependencies, code quality, types, tests and release readiness.
- Logging, monitoring, backups and recovery procedures appropriate to the service and its risks.
- Assessment and limitation of providers that process data on our behalf.
We reassess safeguards as features, threats and technology change. We do not publish operational detail that could make abuse easier.
Detection, response and recovery
For a potential incident, we first establish the facts, restrict access or impact and restore secure operation. We then assess the cause, consequences and improvements.
Where personal data may be affected, we follow our data-breach process and notify affected people and the Dutch Data Protection Authority when risk and law require it.
Responsible disclosure
If you believe you found a vulnerability, send a clear description, reproduction steps and potential impact. Do not access other people’s data or publish the finding before we have had a reasonable opportunity to investigate.
We acknowledge reports, prioritise their review and keep you informed where possible. We treat good-faith reports that follow these principles carefully and respectfully.
Reports and further information
Report a potential vulnerability with “Security” in the subject line.
Email the security teamThe personal data we use and the rights available to you.
Privacy statementHelp with the app or your account.
Support