Trust and security, without fake certifications

ABH is a billing-first product, so trust matters. This page covers the real technical and operational choices behind the product without pretending to be a compliance giant.

What is true today

  • Hosted on Hetzner infrastructure in Germany
  • Cloudflare used for CDN, DDoS protection, and Turnstile CAPTCHA
  • Transactional email delivered through Resend
  • ABH subscription billing handled by Polar
  • No payment card data stored directly by ABH

Security measures documented in the product

  • HTTPS/TLS for data in transit
  • Bcrypt password hashing
  • Role-based access controls
  • Multi-tenant data isolation
  • Rate limiting on authentication endpoints
  • JWT invalidation after password changes
  • File-upload validation and re-encoding safeguards

What ABH does not claim

ABH does not claim SOC 2, ISO 27001, HIPAA, bank-grade security, or zero risk. The goal is to be clear about the protections that exist now and avoid overclaiming.

Helpful trust details for buyers

Privacy and data rights

The app includes a GDPR data export path and public privacy, terms, cookie, and refund policies.

Billing separation

ABH subscriptions are billed through Polar. Client invoice payments are still collected through your own external payment method.

Founder-operated product

This is an early, founder-operated SaaS. The product is being improved around real billing workflows rather than inflated enterprise claims.

Frequently asked questions

Does ABH store my card details?

No. ABH subscriptions are billed through Polar, which handles payment details and subscription billing outside the app.

Can I export my data?

Yes. The app includes export capabilities, including GDPR-oriented personal data export and plan-based billing and reporting exports.

Create your first proof-backed invoice

Start with one client, one project, and one clearer invoice.