We take the security of your data and your cloud accounts seriously. Here's exactly how we protect both.
LessBill was designed with a minimal-footprint principle: we request only the permissions we need, we store only what is necessary to provide the service, and we apply defense-in-depth controls at every layer of the stack. We believe that the best way to keep your data safe is to limit what we access and retain in the first place.
We are committed to transparency about how we handle security. If you have questions not answered here, please reach out at hello@lessbill.org.
All data stored by LessBill is encrypted at rest using AES-256. All data transmitted between your browser and our servers, and between our servers and cloud provider APIs, is encrypted in transit using TLS 1.2 or higher. We do not support older, insecure protocol versions.
All data stored in our databases and object storage is encrypted at rest using AES-256, managed through AWS Key Management Service (KMS) with customer-isolated keys.
All connections to the LessBill application and API are encrypted using TLS 1.2 or TLS 1.3. We reject connections using older SSL/TLS versions and enforce HTTPS across all endpoints.
LessBill accesses your cloud accounts using read-only IAM roles. We request the minimum permissions required to retrieve cost and usage data and resource metadata. We never request, accept, or exercise any write permissions to your cloud infrastructure.
This means LessBill cannot create, modify, or delete any resources in your cloud accounts. It cannot access the contents of your databases, object storage, or any application data. It only ever reads billing records and resource metadata — the same information you can see in your cloud provider's billing console.
We never store your cloud provider root credentials or access keys. LessBill connects using cross-account IAM roles (for AWS) and equivalent role-based mechanisms for GCP and Azure. You can revoke our access at any time by deleting the IAM role in your cloud account.
Access to customer data within LessBill is restricted on a need-to-know basis. Engineers do not have standing access to production customer data. All privileged access is logged and audited.
All LessBill accounts support multi-factor authentication (MFA). We enforce strong password requirements and rate-limit authentication attempts to mitigate brute-force attacks.
LessBill's infrastructure runs on Amazon Web Services (AWS), which maintains SOC 2 Type II, ISO 27001, and numerous other compliance certifications. Our primary data region is eu-west-1 (Ireland).
Our key infrastructure and service partners include:
Compute, database, storage, and networking infrastructure. SOC 2 Type II, ISO 27001, PCI DSS, and GDPR compliant.
Payment processing. PCI DSS Level 1 certified Service Provider. We never handle or store raw payment card data.
We conduct regular reviews of our infrastructure configuration, dependency security, and access controls. Our engineering team applies security patches to all systems within a defined SLA based on severity.
If you discover a security vulnerability in LessBill, we ask that you report it to us privately so that we can address it before it can be exploited. We are committed to working with security researchers in good faith.
To report a vulnerability, email us at security@lessbill.org. Please include a description of the issue, the steps required to reproduce it, and any supporting evidence (screenshots, proof-of-concept code). We will acknowledge your report within 48 hours and keep you informed as we investigate and resolve the issue.
We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it — typically 90 days from the date of your report. We will not take legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy.