SOC 2 company profile

BILL SOC 2 status and provider evidence

Review BILL’s public SOC 2 statement, report type, evidence source, and freshness.

SOC 2 statusself attested
Report typeType II
Providers found0
Last checked2026-08-30
Providers

BILL’s SOC 2 stack

No provider is named on the current source.

We will update this page if the company publishes more detail.

Compliance coverage

Frameworks named by BILL

HIPAA

dustry Data Security Standard (PCI DSS), ensuring sensitive card data is safe and only accessible to authorized users. Health Insurance Portability and Accountability Act of 1996 (HIPAA): For healthcare organizations that need to maintain compliance with HIPAA, BILL Accounts Payable and Accounts Receivable provides safeguards for electronic protected health information (ePHI).‍Anti-Money Laundering (AML)/OFAC program: BILL maintains AML and

Checked 2026-08-30
View source ↗
PCI DSS

tracts.Compliance protections SOC 1 and SOC 2 Type II: BILL meets SOC 1 and SOC 2 Type II standards, established by the American Institute of Certified Public Accountants (AICPA). PCI Level-1 Certification: BILL undergoes an annual audit by an independent Qualified Security Assessor (QSA). PCI Level-1 compliance is the highest level of certification under the Payment Card Industry Data Security Standard (PCI DSS), ensuring sensitive card d

Checked 2026-08-30
View source ↗
SOC 1

ties managed by leading certified data center providers.BILL Spend & Expense world-class spend management software is free, with no hidden fees or contracts.Compliance protections SOC 1 and SOC 2 Type II: BILL meets SOC 1 and SOC 2 Type II standards, established by the American Institute of Certified Public Accountants (AICPA). PCI Level-1 Certification: BILL undergoes an annual audit by an independent Qualified Security Assessor (QSA). PCI

Checked 2026-08-30
View source ↗
SOC 2

ed by leading certified data center providers.BILL Spend & Expense world-class spend management software is free, with no hidden fees or contracts.Compliance protections SOC 1 and SOC 2 Type II: BILL meets SOC 1 and SOC 2 Type II standards, established by the American Institute of Certified Public Accountants (AICPA). PCI Level-1 Certification: BILL undergoes an annual audit by an independent Qualified Security Assessor (QSA). PCI Level-1 co

Checked 2026-08-30
View source ↗

Primary compliance evidence

BILL public statement

ed by leading certified data center providers.BILL Spend & Expense world-class spend management software is free, with no hidden fees or contracts.Compliance protections SOC 1 and SOC 2 Type II: BILL meets SOC 1 and SOC 2 Type II standards, established by the American Institute of Certified Public Accountants (AICPA). PCI Level-1 Certification: BILL undergoes an annual audit by an independent Qualified Security Assessor (QSA). PCI Level-1 compliance

Classification: self attested · checked 2026-08-30
Open source ↗
SOC 1SOC 2SOC 3Type IType IIAudit readinessTrust centersVendor riskSecurity evidenceProcurement