Security
Security and connection transparency
BillFound uses connected work sources and billing sources in a read-only production posture. It is designed to inspect billing gaps without taking control of your calendar, accounting system, or customer communication.
Current production connection posture
Trust facts
- Google OAuth verification completed.
- Microsoft publisher domain verified.
- Read-only calendar connections.
- No changes to your calendars or books.
BillFound completed Google's OAuth verification process for its requested Google Calendar read-only access. BillFound's publisher domain is verified with Microsoft Entra. These verifications do not imply endorsement by Google or Microsoft.
Google Calendar
- Google OAuth verification completed.
- BillFound requests
https://www.googleapis.com/auth/calendar.calendarlist.readonly. - BillFound requests
https://www.googleapis.com/auth/calendar.events.readonly. - Calendar List read-only access lets you see and select calendars to monitor.
- Calendar Events read-only access lets BillFound read events from calendars you select for billing-gap checks.
- BillFound does not request Google Calendar write access.
- BillFound cannot create, edit, or delete Google Calendar events.
Microsoft Outlook
- BillFound's publisher domain is verified with Microsoft Entra as
billfound.com. - BillFound production OAuth requests delegated
Calendars.Readfor Outlook Calendar access. - BillFound production OAuth does not request
Calendars.ReadWrite. - BillFound reads calendars and events needed for billing-gap checks.
- BillFound does not create, edit, or delete Outlook Calendar events.
BillFound does not claim Microsoft verified-publisher badge status unless that separate Partner verification is completed later.
QuickBooks Online
- BillFound reads relevant customer, invoice, and accounting records for billing-gap comparison.
- When QuickBooks provides invoice delivery, view, due-date, balance, or open-status fields, BillFound may display them in the read-only Invoice Follow-up view.
- BillFound does not create invoices.
- BillFound does not edit customers.
- BillFound does not modify QuickBooks Online records.
- BillFound does not collect customer payments.
QuickBooks-reported delivery or view status is informational. It is not proof that an invoice was legally delivered, personally read, collectible, or owed. BillFound is independent software and does not imply Intuit endorsement.
Xero
- BillFound requests
offline_access,accounting.contacts.read, andaccounting.invoices.read. - BillFound uses read-only accounting, contact, and invoice access for BillFound checks.
- BillFound does not request Xero write access.
- BillFound does not create or modify Xero invoices.
BillFound is independent software and does not imply Xero endorsement.
Stripe
- BillFound subscription checkout is handled through Stripe.
- Stripe is used for BillFound subscription billing only.
- BillFound does not collect payments from your customers.
BillFound does not imply Stripe endorsement.
What BillFound never does
- Does not contact your customers.
- Does not send invoices.
- Does not create invoices automatically.
- Does not change connected accounting records.
- Does not create, edit, or delete connected calendar events.
- Does not collect your customers' payments.
- Does not make legal determinations about whether money is owed.
Disconnect and deletion
You can disconnect Google Calendar, Outlook Calendar, QuickBooks Online, or Xero from Connections in BillFound. Disconnecting deletes BillFound's stored OAuth credential for that provider and stops future access. You can also revoke BillFound directly from the provider account settings.
For help, privacy details, or account and data deletion requests, use Support, the Privacy Policy, or Data Deletion.
Technical details
OAuth client IDs are public identifiers, not secrets. They can help cautious buyers compare a consent screen with BillFound's documented production configuration.
- Production Google OAuth client ID:
521544765068-opeldmhndr737bn8or0tfdql41en0ltn.apps.googleusercontent.com. - Production Microsoft application/client ID:
83c47253-a2de-4d51-abbe-1044a220381a.
BillFound does not publish client secrets, refresh tokens, webhook secrets, Stripe keys, encryption keys, or private deployment identifiers.
