Skip to content

Trust

Billing is critical infrastructure. We treat it that way.

Occurly holds the record your revenue is computed from. This page states what protects it, how the platform is built to keep it available, and who to ask for the rest.

Controls

What is actually in place.

Data protection

  • TLS 1.2 or higher in transit, AES-256 at rest
  • Per-tenant logical isolation on every query path
  • Field-level encryption for personal and payment data
  • Encrypted, tested backups with point-in-time recovery

Access

  • SSO and SCIM provisioning on Scale and Enterprise
  • Role-based access control down to the object
  • Least-privilege internal access, reviewed quarterly
  • Immutable audit log of every read and write, exportable

Payments

  • Card data is tokenized and vaulted with PCI-DSS processors
  • Occurly never stores a primary account number
  • SCA and 3D Secure handled at the gateway
  • Processor-agnostic routing, so nothing is re-vaulted on a switch

Engineering

  • Peer review and automated checks on every change
  • Dependency and container scanning in the pipeline
  • Annual third-party penetration test
  • Documented incident response with customer notification targets

Compliance

Where each programme stands.

Stated literally, including the ones that are not finished. A security reviewer would rather read "in progress" than find out later.

Occurly compliance posture
Programme Status Detail
PCI DSS Inherited Card data never touches Occurly. Handled by PCI-DSS Level 1 processors.
GDPR Supported DPA available, standard contractual clauses, documented subprocessors.
Audit evidence Under NDA Control documentation and audit evidence are shared during vendor review.
Penetration testing Annual Third-party test each year, with the summary available on request.
Data residency On request Regional hosting available on Enterprise agreements.

Reliability

A billing cycle does not wait.

Invoicing runs on a calendar the business does not control, so the platform is built to degrade rather than stop: queued writes are idempotent, webhooks are replayable, and a failed region does not become a missed cycle.

Contracted uptime on Enterprise
99.99%
Redundancy, with tested failover
Multi-AZ
  • Idempotency keys on every write path
  • Signed webhooks, retried and replayable
  • Point-in-time recovery from encrypted backups
  • Restore procedures tested, not assumed

Security FAQ

What reviewers ask.

The questions that arrive on every vendor questionnaire, answered before you send it.

Where is our data hosted?

On managed cloud infrastructure with redundancy across availability zones. Enterprise agreements can pin processing and storage to a named region, which matters where local rules require it.

Do you store card numbers?

No. Payment methods are tokenized and vaulted by PCI-DSS Level 1 processors, and Occurly stores only the token and the display metadata a customer needs to recognise their card. Because routing is processor-agnostic, changing gateway does not mean re-collecting payment details from your customers.

Can we get an audit trail for a specific invoice?

Yes. Every read and write against a billing object is logged with actor, timestamp and the before and after state. The log is immutable, queryable, and exportable on Scale and Enterprise, which is normally what an auditor asks for first.

What happens during an incident?

Documented incident response with named owners, status published to the status page as it develops, and direct notification to affected customers within the timelines in your agreement. A written post-incident review follows.

How do we run a vendor security review?

Contact us and we will return the questionnaire, the DPA, the subprocessor list and, where a report exists, the audit evidence under NDA. Reviews are answered within two business days.

What happens to our data if we leave?

Your data stays yours. Full export of customers, subscriptions, invoices and usage records in machine-readable form at any time, and deletion on request within the window set out in the DPA.

Send us your questionnaire.

We answer vendor security reviews within two business days, with evidence attached where a report exists.