Security
Billing data is financial data. We treat it that way.
Morag holds your customers, your rate cards and your supplier costs. Here is how that is protected today — and, just as importantly, what we do not claim.
What is in place
- Access control
- Role-based permissions on every endpoint, with multi-factor authentication enforced for privileged roles. Customer-facing access runs through a separately authenticated portal with its own, narrower permissions.
- Tenant scoping
- Billing data is scoped to the owning tenant in the application layer: queries are constrained server-side rather than filtered in the browser, and customer-facing endpoints are limited to the authenticated account. Database-level row security is not currently relied on as the primary control — the application layer is.
- Auditability
- Billing runs are immutable. A correction is a credit note and a fresh invoice, never a silent edit, and rates, plans and charges keep a change history — so any figure on any invoice can be traced back to the record and the change that produced it.
- Backups
- Timestamped database snapshots, plus an internal indicator that warns when a backup has not succeeded in the last 24 hours. Every billing run is additionally archived as a self-contained snapshot of what was billed and why.
- Hosting and data handling
- Billing data is held in managed Postgres hosted in a London region, reached over encrypted connections, with encryption at rest provided by the managed platform. We ask for the data needed to bill and reconcile, and nothing else.
- Health-check files
- Files you send for a free billing health check are transferred by arrangement rather than through this website, are used only for that analysis, are not shared outside our team, and are deleted once it is complete.
What we do not claim
Plenty of vendors imply more than they hold. These are the things Morag does not have, stated here so you do not have to find out during procurement:
- No ISO 27001, SOC 2 or equivalent certification, and no independent third-party assurance.
- No published uptime figure or availability SLA on this website.
- No claim of a formally tested disaster-recovery process.
- No claim that credit notes or invoicing have been formally verified as HMRC-compliant — the workflows are designed around UK invoicing requirements, which is not the same thing.
In progress
Security questionnaires
If your procurement process needs a security questionnaire completed, send it over and we will answer it in full — including the questions where the honest answer is 'not yet'. We would rather lose a deal on an accurate answer than win one on a vague one.
Responsible disclosure
If you believe you have found a vulnerability, email hello@moragbilling.com and we will acknowledge it within one working day. We will not pursue anyone acting in good faith.
