What is true today, and what is not yet
You are being asked to send commercial documents to a small company. The useful version of this page separates what is actually running from what is intended — so everything below carries one of two marks, and nothing planned is written as though it were done.
Where your data is
| What | Where | Status |
|---|---|---|
| The database — invoices, shipments, findings, claims | Our own server in Germany (Hetzner, Falkenstein) | in place |
| Your uploaded documents | The same server, in Germany | in place |
| Documents moving to dedicated object storage | Cloudflare R2, EU jurisdiction | planned |
| Backups — encrypted, nightly, with a restore drill | Held with the server today | in place |
| An offsite copy of those backups | Backblaze B2, EU (Netherlands) | planned |
| This website | Cloudflare's network. It holds no customer data at all | in place |
We do not say "UK hosted", because it would not be true. The database is in Germany, inside the EU.
How the system is reached
| No open web port | The server accepts no inbound web traffic. It opens an outbound tunnel to Cloudflare instead, so there is no public address to attack. Administrative access is restricted by network and by key. in place |
| The database is never on the internet | It is reachable only by the application containers on the machine's internal network. in place |
| Sign-in | No passwords. A link sent to your email address, or Google sign-in. Sessions expire and can be revoked. in place |
| Multi-factor authentication | Required for administrative accounts. planned |
| Separation between customers | Enforced twice: in the application, and independently by the database itself. Both have to agree before a row moves, and an automated test suite proves it on every change. in place |
| Production data on laptops | Never. in place |
AI, and what it is not allowed to touch
Models are used to read documents at setup — which file is what, what your discount letter says — and every reading is confirmed by a person before it counts. The checks themselves never involve a model.
- External model processing is off by default and is switched on per customer, in writing. in place
- Where it is switched on, document pages may be sent to a model provider in the United States under a retention configuration we verify. You would be told which provider, and you can decline.
- Your documents are never used to train anything, by us or by a provider.
- A model never decides that a charge is wrong. It cannot: findings come from versioned rules in the database.
Sub-processors
Everyone who could touch your data, and why.
| Who | Where | What for |
|---|---|---|
| Hetzner | Falkenstein, Germany | The server the product runs on |
| Cloudflare | EU / global network | DNS, this website, the tunnel, email routing |
| Postmark | United States | Sign-in and notification email |
| Backblaze | Netherlands | Offsite backups planned |
| Anthropic or OpenAI | United States | Document reading, only where you have switched it on |
Recovery, and the honest version of it
| Backups | Nightly, encrypted, de-duplicated, with a weekly drill that actually restores them rather than assuming they work. in place |
| Offsite copy | The backups sit with the server today, which protects against a bad change but not against losing the machine. A second copy in the Netherlands is the next thing on the list. planned |
| Recovery objectives | Target: at most 24 hours of data lost, back up within 4 hours. Stated as a target, and it assumes a person is awake — there is one of us. target |
| Deploys | Every release is verified after it lands and rolled back automatically if it does not answer. in place |
| Monitoring and alerting | External uptime checks and failure alerts. planned |
Certifications and paperwork
None of these is in place. They are listed so you know where we are rather than having to ask.
| Cyber Essentials | planned |
| Independent penetration test | planned — before the first mid-size contract |
| ISO 27001 / SOC 2 | Not held, and not being pursued until a contract requires it |
| Data processing agreement | We will sign one before you send anything. Just ask |
| NDA | Happy to sign one first |
| Deletion on request | Ask, and we delete and confirm. in place |
Found a problem?
Email security@overbill.co.uk. We will acknowledge it, we will not threaten you, and we will tell you when it is fixed. If you are a customer and something has gone wrong with your data, we will tell you what we know without waiting until we know everything.
Last reviewed 7 September 2026. If something on this page has gone out of date, that is a bug — please tell us.