Executive Summary
AI-generated analysis for Bill.com
Bill.com (BILL Holdings, Inc.) is an established financial operations platform incorporated in Delaware and actively registered with a verified LEI. At Risk Tier 3 (Moderate Risk), the platform presents a broadly acceptable security posture with several notable strengths, tempered by transparency gaps that require remediation before this relationship can be considered fully documented for compliance purposes. Positive signals across the investigation are meaningful:
Key Findings
- Bill.com's domain has been registered since 1994 (~31 years), indicating a deeply established online presence.
- Infrastructure exposure is minimal: only 2 open ports (80 and 443) are detected with zero known CVEs — well below the SaaS industry average of 8–12 open ports, representing a tightly controlled perimeter.
- The domain IP carries a clean abuse reputation (0% abuse score), no threat intelligence pulses, no malware or phishing flags via Malware detection service, and a clean web security scanning service result.
- The company claims annual SOC 1 and SOC 2 Type II audits conducted by a national CPA firm, as stated on their public security page (https://bill.com/security).
- No sanctions matches, no adverse media in the current or historical windows, and no SEC enforcement filings were identified. Several gaps require attention before this vendor relationship is fully risk-documented:
- Bill.com's security header implementation on the public-facing marketing site (bill.com) is graded D+ by HTTP security scanner, with 5 failed tests. While the application endpoint (app.bill.com) may have a stronger posture, this has not been independently verified in this investigation.
- No publicly accessible subprocessor list was found. For a financial operations platform with medium data access, this limits supply chain visibility and creates a potential gap for GDPR Article 28 compliance documentation.
- Both SOC 1 and SOC 2 certifications are vendor-attested only — claimed on the trust page but not independently verifiable through a public registry. The actual audit reports have not been reviewed.
- Bill.com's AI data usage policy does not clearly state whether customer data is used for model training or specify retention periods for AI-processed data. Given the sensitivity of financial operations data, this ambiguity is a material concern. Overall, Bill.com presents as a commercially mature, well-established vendor with a clean threat and sanctions profile. The Tier 3 rating reflects transparency and documentation gaps rather than active risk signals. Conditional approval is appropriate, subject to obtaining the SOC 2 Type II report and clarification on AI data handling practices.
Independence Statement
All evidence in this report was independently sourced from external registries, threat intelligence feeds, DNS infrastructure, and public web sources without vendor participation or input.