Security and data protection in Bilify

How Bilify keeps each company's data separate, controls who can sign in and what they can do, records changes, and protects links, API keys and webhooks.

5 min read Updated 04.10.2026

Invoices hold sensitive information about you and your clients. This page explains, in plain terms, how Bilify protects it: how companies are kept apart, how people sign in, who can do what, what is recorded, and how links and integrations are secured. It describes how the product works; it is not a certification.

Each company's data is kept separate

Every record in Bilify (clients, documents, products, expenses, files and settings) belongs to exactly one company. Each screen and each API call works inside the company you are signed in to and only reads and writes that company's records. If you belong to several companies, you switch between them explicitly, and each has its own data, members and settings.

The client portal works the same way: a client contact signs in to one company's portal and only sees what that company has shared with that client.

Signing in

  • Verified email. A new account must confirm its email address through a link before it can open the app. If you change your email address, you confirm the new one the same way.
  • Passwords are stored as one-way hashes, never in readable form. Repeated failed sign-in attempts are slowed down.
  • Passkeys. You can sign in with your fingerprint, face or device PIN instead of a password. Add one under Account > Passkeys. A passkey never leaves your device.
  • Google and Apple sign-in, when offered on the sign-in page. A social account is linked to an existing Bilify account only when the provider confirms the same email address.
  • Clients sign in without a password. Portal contacts get a sign-in link by email. The link works once and expires after 15 minutes.

Two-factor codes

Bilify does not offer one-time codes from an authenticator app for signing in. Passkeys are the strongest sign-in option available today.

Roles and permissions

Every member of a company has a role, and every screen and action checks a specific permission before it opens:

Role What it can do
Owner Everything, including billing and members.
Admin Everything except managing billing.
Accountant Documents, clients, products, expenses, reports, contracts and e-Faktura. Cannot manage members, company settings or integrations.
Employee Create and edit drafts and clients, add expenses and view lists. Cannot issue documents.

See Roles and permissions for the full list.

Every important change is recorded

The activity log records who did what and when: issuing, cancelling and deleting documents, changes to clients and settings, member changes, API and AI assistant actions, client portal sign-ins and more. The activity log is included in every package.

If Bilify support ever signs in to your company as one of your users to help with a problem, the start and end of that session are recorded in your company's activity log.

Nothing is permanently deleted

  • Issued documents are locked. After issue, the lines, totals and the client and company details on a document cannot change. Issued fiscal documents are cancelled, never deleted, and keep their number.
  • Delete means archive. When you delete a client, product, expense or draft, it moves out of the list and can be restored. No role, including the owner, can permanently erase records from inside the product.
  • Stock history is append-only. A stock correction is a new movement, never an edit of an old one.

Links Bilify sends by email are signed, so they cannot be altered, and they expire:

Link Valid for
Client portal sign-in link 15 minutes, single use
Link to a single document sent to a client 30 days
Report links in scheduled report emails 7 days
Export download right after you export 30 minutes

Contract signers confirm their signature with a 6-digit code sent to their email address. The code expires after 10 minutes and allows a limited number of attempts. After everyone has signed, the contract is sealed into a PDF with an audit page that includes a fingerprint (SHA-256) of the signed content. This is a simple electronic signature, not a qualified electronic signature.

API keys, webhooks and AI assistants

Requires: REST API & webhooks, AI assistant connector (MCP)

  • API keys are shown once, when you create them, and stored only as a hash. You can revoke a key at once, or roll it: the new key starts working immediately and the old one keeps working for 24 hours so you can swap it without downtime. A key acts with the permissions of the member who created it, and requests are rate limited. Live keys and sandbox keys are separate.
  • Webhooks are signed. Each delivery carries an X-Bilify-Signature header with a timestamp and an HMAC-SHA256 signature made with your endpoint's secret, so your server can check that the message came from Bilify and was not replayed. See Verify webhook signatures.
  • AI assistants connect through OAuth. You approve each connection with your own account, choose the one company it may use, and can revoke it at any time. The assistant has your permissions and its actions appear in the activity log.

Secrets and files

  • Your e-Faktura certificate and its password, and the API key of your own email provider, are stored encrypted and are never sent back to the browser.
  • Uploaded files (logos, receipts, contract PDFs) are kept in Bilify's file storage, which the platform runs on its own servers or on S3-compatible object storage.

Frequently asked questions

Can other Bilify customers see my data?

No. Every record belongs to one company and the app only reads and writes the records of the company you are working in.

Can Bilify staff see my data?

Bilify platform administrators can open a company to provide support, including signing in as one of its users. When they sign in as a user, the session is recorded in your company's activity log.

Is Bilify certified (ISO 27001, SOC 2)?

Bilify does not claim any security certification. If your organization needs specific assurances, write to us through the contact page.

What happens to my data if I delete something by mistake?

Deleted clients, products, expenses and drafts can be restored. Issued documents cannot be deleted at all; they can only be cancelled.

Does Bilify use two-factor authentication?

There are no authenticator-app codes. You can use passkeys, which replace the password with your device's fingerprint, face or PIN.

Where is my data stored?

In Bilify's database and file storage. The hosting provider and location are not listed in this help centre; ask us through the contact page if you need them.