Enterprise-grade infrastructure

Security you can
build a quote on.

Billable CPQ is layered by design — a global edge network, SOC 2 Type 2 infrastructure, row-level data isolation, AES-256 at rest, and TLS 1.3 in transit. Here's the full stack — layer by layer.

Download the full overview (PDF) ↓ [email protected]
Built on
Cloudflare
Supabase
AWS
What runs where

Three providers. Every one audited.

We don't roll our own infrastructure. Billable CPQ runs on three independently audited platforms that each carry active third-party security certifications.

Cloudflare Pages

Frontend · Edge · CDN

Static site hosting, global edge routing, TLS termination, DDoS mitigation, and Web Application Firewall. 330+ data centers worldwide.

SOC 2 Type 2 ISO 27001 PCI DSS

Supabase

Database · Auth · API

Postgres-based backend platform — authentication, REST/GraphQL API, storage, and Edge Functions. Isolated Postgres instance per project; not multi-tenant shared.

SOC 2 Type 2 HIPAA available GDPR tooling

Amazon Web Services

Underlying compute · storage

Supabase runs exclusively on AWS across 17 global regions on Graviton processors. Physical security, hypervisor isolation, and hardware controls inherited from AWS.

SOC 1/2/3 ISO 27001/17/18 FedRAMP PCI DSS L1
Compliance

What we have. What we don't.

We believe buyers deserve a straight answer, not marketing fog. Here's exactly where Billable CPQ stands on compliance today and where we're headed.

Inherited from our infrastructure

Billable CPQ runs on top of SOC 2 Type 2 audited infrastructure (Supabase + AWS + Cloudflare), which means the environment hosting your data is audited annually by independent third parties. The same building blocks used by mature B2B SaaS companies are in place from day one.

What Billable itself holds today

Transparency: Billable CPQ is early-stage and does not currently hold an independent SOC 2 Type 2 audit for our application layer. The infrastructure controls above are in place; a formal Billable-specific SOC 2 audit is on our roadmap as the customer base justifies the cost.

For customers who need Billable-specific attestation today, we're happy to complete security questionnaires, walk through our architecture on a call, and share specific configuration details under NDA.

✓ SOC 2 Type 2
via Supabase · audited annually
✓ SOC 1/2/3 · ISO 27001
via AWS · underlying compute
✓ ISO 27001 · PCI DSS
via Cloudflare · edge layer
✓ Data-subject request tooling
via Supabase · for access & deletion requests