Overbill
Security and data

What is true today, and what is not yet

You are being asked to send commercial documents to a small company. The useful version of this page separates what is actually running from what is intended — so everything below carries one of two marks, and nothing planned is written as though it were done.

in place planned

Where your data is

WhatWhereStatus
The database — invoices, shipments, findings, claims Our own server in Germany (Hetzner, Falkenstein)in place
Your uploaded documents The same server, in Germanyin place
Documents moving to dedicated object storage Cloudflare R2, EU jurisdictionplanned
Backups — encrypted, nightly, with a restore drill Held with the server todayin place
An offsite copy of those backups Backblaze B2, EU (Netherlands)planned
This website Cloudflare's network. It holds no customer data at allin place

We do not say "UK hosted", because it would not be true. The database is in Germany, inside the EU.

How the system is reached

No open web port The server accepts no inbound web traffic. It opens an outbound tunnel to Cloudflare instead, so there is no public address to attack. Administrative access is restricted by network and by key. in place
The database is never on the internet It is reachable only by the application containers on the machine's internal network. in place
Sign-in No passwords. A link sent to your email address, or Google sign-in. Sessions expire and can be revoked. in place
Multi-factor authentication Required for administrative accounts. planned
Separation between customers Enforced twice: in the application, and independently by the database itself. Both have to agree before a row moves, and an automated test suite proves it on every change. in place
Production data on laptops Never. in place

AI, and what it is not allowed to touch

Models are used to read documents at setup — which file is what, what your discount letter says — and every reading is confirmed by a person before it counts. The checks themselves never involve a model.

  • External model processing is off by default and is switched on per customer, in writing. in place
  • Where it is switched on, document pages may be sent to a model provider in the United States under a retention configuration we verify. You would be told which provider, and you can decline.
  • Your documents are never used to train anything, by us or by a provider.
  • A model never decides that a charge is wrong. It cannot: findings come from versioned rules in the database.

Sub-processors

Everyone who could touch your data, and why.

WhoWhereWhat for
HetznerFalkenstein, GermanyThe server the product runs on
CloudflareEU / global networkDNS, this website, the tunnel, email routing
PostmarkUnited StatesSign-in and notification email
BackblazeNetherlandsOffsite backups planned
Anthropic or OpenAIUnited StatesDocument reading, only where you have switched it on

Recovery, and the honest version of it

Backups Nightly, encrypted, de-duplicated, with a weekly drill that actually restores them rather than assuming they work. in place
Offsite copy The backups sit with the server today, which protects against a bad change but not against losing the machine. A second copy in the Netherlands is the next thing on the list. planned
Recovery objectives Target: at most 24 hours of data lost, back up within 4 hours. Stated as a target, and it assumes a person is awake — there is one of us. target
Deploys Every release is verified after it lands and rolled back automatically if it does not answer. in place
Monitoring and alerting External uptime checks and failure alerts. planned

Certifications and paperwork

None of these is in place. They are listed so you know where we are rather than having to ask.

Cyber Essentialsplanned
Independent penetration testplanned — before the first mid-size contract
ISO 27001 / SOC 2Not held, and not being pursued until a contract requires it
Data processing agreementWe will sign one before you send anything. Just ask
NDAHappy to sign one first
Deletion on requestAsk, and we delete and confirm. in place

Found a problem?

Email security@overbill.co.uk. We will acknowledge it, we will not threaten you, and we will tell you when it is fixed. If you are a customer and something has gone wrong with your data, we will tell you what we know without waiting until we know everything.

Last reviewed 7 September 2026. If something on this page has gone out of date, that is a bug — please tell us.