Responsible disclosure
Version 1.0 — August 21, 2026
AirBill processes financial data for business owners and accounting firms. We actively look for vulnerabilities in our own systems, but no system is perfect. If you have found a weakness in AirBill, we would like to hear from you so we can fix it quickly. This policy follows the Dutch NCSC Coordinated Vulnerability Disclosure guideline.
1. How to report a vulnerability
Send your report to security@airbill.app. Describe the issue as concretely as you can so that we can reproduce it:
- which component is affected (website, accountant portal, API, iOS or Android app);
- the steps to reproduce it, with screenshots or a proof of concept where useful;
- what an attacker could do with it;
- how we can reach you with questions.
A machine-readable pointer to this policy is published at /.well-known/security.txt (RFC 9116).
2. Scope
- www.airbill.app and all subdomains of airbill.app;
- the accountant portal at acc.airbill.app;
- the AirBill API;
- the AirBill apps on the App Store and Google Play.
Out of scope are the third-party services we build on (such as our hosting providers, payment provider and e-mail providers); please report vulnerabilities in those to the provider concerned. Reports without a demonstrable security impact — such as missing best-practice headers without an exploit, version numbers in error messages, or clickjacking on pages without sensitive actions — are not treated as vulnerabilities.
3. What we ask of you
- Do not go further than necessary to demonstrate the vulnerability. Use only your own (test) account and do not access other users' data.
- If you do come across personal or financial data belonging to others, stop immediately and report it.
- Do not modify, copy or delete data, and do not install backdoors.
- Do not perform (D)DoS attacks, social engineering, phishing, spam or physical attacks.
- Do not disclose the vulnerability publicly until we have fixed it and agreed the disclosure with you.
4. What you can expect from us
- We confirm receipt of your report within two working days.
- Within five working days we give an initial assessment and an expected timeline for the fix.
- We keep you informed of progress and let you know when the issue is resolved.
- We treat your report confidentially and do not share your details with third parties without your consent, unless required by law.
- If you follow the rules above, we will not take legal action against you in connection with your research.
- If you wish, we credit you as the discoverer once the issue is resolved.
5. Contact
Tally AI B.V. (AirBill), Schipluidenlaan 4, 1062 HE Amsterdam, Chamber of Commerce 99443570. Security reports: security@airbill.app. Other questions: support@airbill.app.