Your invoices hold real business and client data, so security isn't an afterthought. Here's what we do.
Encryption in transit
Every connection to InvoiceBadger is over HTTPS/TLS, enforced with HSTS. Your data is never sent in the clear.
Passwords
Passwords are hashed with PBKDF2-HMAC-SHA256 and a unique salt per account. We never store them in plain text and can't see them, so even we can't tell you your password, only help you reset it.
Your data is isolated
Every record belongs to one account, and that ownership check is enforced down in the database layer of every query, not just in the interface. One account can't read or touch another's data.
Sessions and account control
Sign-in uses a signed, HttpOnly, Secure session cookie. You can log out of every device at once, and deleting your account permanently removes your data.
Infrastructure
InvoiceBadger runs entirely on Cloudflare's network, with the database stored in the EU and automated point-in-time backups. There are no servers of ours sitting around to be misconfigured.
Payments
Card payments are handled by Stripe, a PCI-DSS Level 1 provider. Card numbers go straight to Stripe; they never touch our systems.
Abuse protection
Sign-up and sensitive actions are rate-limited and protected by a privacy-friendly bot check, and every page is served with a strict set of security headers.
Reporting a vulnerability
Found something? We'd genuinely like to hear from you. Email support@invoicebadger.com (also listed in our security.txt) and we'll work with you in good faith to fix it.
An honest note
No online service is perfectly secure, and anyone who tells you otherwise is selling something. We keep improving, and we tell users promptly if anything material happens to their data.