Trust

Security

How we keep your invoicing data safe. Plain English, no hand-waving.

Last updated 26 July 2026

Your invoices hold real business and client data, so security isn't an afterthought. Here's what we do.

Encryption in transit

Every connection to InvoiceBadger is over HTTPS/TLS, enforced with HSTS. Your data is never sent in the clear.

Passwords

Passwords are hashed with PBKDF2-HMAC-SHA256 and a unique salt per account. We never store them in plain text and can't see them, so even we can't tell you your password, only help you reset it.

Your data is isolated

Every record belongs to one account, and that ownership check is enforced down in the database layer of every query, not just in the interface. One account can't read or touch another's data.

Sessions and account control

Sign-in uses a signed, HttpOnly, Secure session cookie. You can log out of every device at once, and deleting your account permanently removes your data.

Infrastructure

InvoiceBadger runs entirely on Cloudflare's network, with the database stored in the EU and automated point-in-time backups. There are no servers of ours sitting around to be misconfigured.

Payments

Card payments are handled by Stripe, a PCI-DSS Level 1 provider. Card numbers go straight to Stripe; they never touch our systems.

Abuse protection

Sign-up and sensitive actions are rate-limited and protected by a privacy-friendly bot check, and every page is served with a strict set of security headers.

Reporting a vulnerability

Found something? We'd genuinely like to hear from you. Email support@invoicebadger.com (also listed in our security.txt) and we'll work with you in good faith to fix it.

An honest note

No online service is perfectly secure, and anyone who tells you otherwise is selling something. We keep improving, and we tell users promptly if anything material happens to their data.

Give the boring bit to a badger.

Free to start. Built for freelancers.

Get started