Last updated: August 8, 2026
Your invoices and customer records are business-critical. Here's how CustomerTab protects them.
Every business gets its own isolated workspace. All data is keyed by business ID, and every API request is checked against the signed-in user's current membership — one business can never read another's customers, invoices, or settings. Team members join only through invite links you generate, and you can revoke access at any time.
Card payments are handled end-to-end by Stripe, a PCI DSS Level 1 certified processor. Card numbers never touch CustomerTab's servers. Online invoice payments go directly to your own Stripe account.
Invoice and reminder emails are sent through Amazon SES with SPF and DKIM authentication on the customertab.com domain.
We run automated alerts on API errors, email failures, and background job health so problems are caught quickly.
If you believe you've found a security issue, email support@customertab.com with details. We take reports seriously and will respond as quickly as we can.