Skip to content
EveryBill

Trust center

What we monitor, and what that does and does not mean

As of 2026-07-28. We run continuous, automated checks against several public security standards. That is real and it is useful. It is not a certification, and we want that distinction to be unmissable before you read anything else on this page.

The distinction that matters most

Continuous monitoring against a standard is not the same thing as certification or attestation against that standard.

Monitoring means automated tooling checks our AWS configuration against a standard’s technical controls on an ongoing basis and tells us where we drift out of line. Certification or attestation means an independent, accredited third party has examined our environment, processes, and evidence and formally signed off that we meet the standard. We do the first. We are not claiming the second anywhere on this site.

What is actually running

We use AWS Security Hub and AWS Config to continuously check our AWS accounts against the technical controls of several published standards. Findings feed our internal remediation process. None of this activity constitutes an external audit.

Standards monitored in AWS Security Hub and AWS Config, verified 2026-07-27/28.
StandardScope monitoredTooling
PCI DSS v4.0.1139 controls monitoredAWS Security Hub
CIS AWS Foundations Benchmark v5.0Enabled and monitoredAWS Security Hub
AWS Foundational Security Best PracticesEnabled and monitoredAWS Security Hub
AWS Config managed rules538 rules, organization-wide aggregatorAWS Config

These counts describe rule and control coverage as configured in our AWS accounts. They are not a pass rate, and we do not publish our current finding count on this page — see the note on the trust hub.

What we do not claim

This section exists on purpose. Saying plainly what we are not claiming is, in our view, the strongest trust signal we can give you, more useful than another badge would be.

  • We do not claim SOC 2 — we have not confirmed whether a report exists, and until legal counsel confirms that, we will not reference it.
  • We do not hold ISO 27001 certification. Our previous website referenced it; that was wrong and it has been removed.
  • We do not claim HIPAA compliance or a signed Business Associate Agreement anywhere on this site, pending confirmation from legal counsel.
  • We do not hold an SSAE 16 attestation. Our previous website referenced SSAE 16 — a standard that was superseded years ago — and that reference was also wrong. It has been removed entirely.
  • We do not claim continuous, automatic, or same-day patching of our infrastructure. Patch deployment today is not fully automated end to end, and we are not going to describe it as though it were.
  • We do not publish an overall security score or a running count of open findings on any public page.

If a claim isn’t in the monitored-standards table above or backed by a specific control on the trust hub, treat it as not yet true.

Monitoring, not certification — verified 2026-07-28

See it running

A short walkthrough of the portal, the admin side, and the deployment option that fits how you handle cardholder data.