Trust center
Our security posture, stated plainly
EveryBill runs payment portals for collections firms, legal practices, and billing operations. This page describes the controls we run today, in AWS, with no rounding up. It is a point-in-time record, not a live dashboard.
Where we stand
As of 2026-07-28. Every control below is backed by a specific AWS service — click through to see the resource-level detail. This page is updated by hand; it is not a real-time feed.
We do not publish an aggregate security score or a running count of open findings on this page. A single number invites false confidence either way, and our internal finding counts change faster than a public page should be trusted to reflect. What follows is the list of controls we can verify and stand behind today.
| Control | What it does | AWS service | Category |
|---|---|---|---|
| Hardware security key on admin access | Administrators cannot sign in to production systems without a physical YubiKey, even if their password is compromised. | AWS IAM Identity Center (SSO) with FIDO2/WebAuthn | Identity & access |
| IAM Access Analyzer | Continuously checks permission policies for unintended external or cross-account access and flags them. | AWS IAM Access Analyzer | Identity & access |
| Per-customer account isolation (Silo / Sovereign) | Each Silo or Sovereign customer's workload runs in its own AWS account, so one customer's environment cannot reach another's. | AWS Organizations, dedicated member accounts | Identity & access |
| Region lock | A written policy blocks any workload from being created outside our approved AWS region, so data cannot silently move to another part of the world. | AWS Organizations Service Control Policy, us-east-1 | Governance |
| Web application firewall | Public-facing sites and portals sit behind a filter that blocks common web attacks before they reach the application. | AWS WAF on public CloudFront/ALB distributions | Network |
| Network traffic logging | Every network connection in and out of production is logged, so investigators can reconstruct what happened after any incident. | VPC Flow Logs on all four production VPCs | Network |
| Minimum TLS version enforcement | Connections to our sites and portals must use a current, secure version of TLS; older, weaker encryption is rejected. | Amazon CloudFront, minimum protocol TLSv1.2_2021 | Network |
| Storage encryption with customer-managed keys | Storage and backups are encrypted using keys we control directly, separated by domain, rather than a single shared default key. This is storage-level encryption; it is not a claim that every individual field is separately encrypted. | AWS KMS, customer-managed keys, 6 aliases in production | Data |
| Managed database with automated backups | The production database replicates across multiple locations automatically and keeps 30 days of backups, with deletion protection turned on so it cannot be dropped by accident. | Amazon Aurora MySQL Serverless v2, Multi-AZ, IAM authentication, not publicly accessible | Resilience |
| Tamper-evident audit trail | Every account activity across the organization is recorded to a log that is encrypted and checked for tampering, covering all regions. | AWS Organization CloudTrail, multi-region, KMS-encrypted, log-file validation enabled | Monitoring |
| Threat detection | Account and network activity is continuously analyzed for signs of compromise, such as unusual API calls or known-bad network addresses. | Amazon GuardDuty | Monitoring |
| Vulnerability scanning | Compute instances, container images, and serverless functions are automatically scanned for known software vulnerabilities. | Amazon Inspector2 (EC2, ECR, Lambda) | Monitoring |
| Configuration monitoring | Resource configurations across the organization are continuously checked against a large rule set, and any resource that drifts out of compliance is flagged. | AWS Config, 538 rules, organization-wide aggregator | Monitoring |
| Security standard monitoring | Our AWS environment is checked automatically against recognized security standards on an ongoing basis, and gaps are surfaced as findings for our team to work. | AWS Security Hub — PCI DSS v4.0.1 (139 controls), CIS AWS Foundations Benchmark v5.0, AWS Foundational Security Best Practices | Monitoring |
This table lists controls we could verify against the live AWS estate. It does not include every control we run, and it is not a certification or attestation. See how we monitor compliance standards for that distinction.
Read the detail
Architecture
How a deployment is built: account isolation, encryption in transit and at rest, backups, and region locking, in plain English.Learn moreCompliance monitoring
What standards we monitor against, what tooling does it, and the difference between monitoring and certification.Learn moreSubprocessors
The infrastructure vendors involved in running EveryBill, and what is still pending confirmation.Learn moreVulnerability disclosure
How to report a security issue in good faith, what is in scope, and how fast we respond.Learn more
Report a problem
If you believe you have found a security issue, do not wait for a scheduled review. See our disclosure process or email info@everybill.com directly.
See it running
A short walkthrough of the portal, the admin side, and the deployment option that fits how you handle cardholder data.