Bill.com
United States · www.bill.com · 28 vendors
BILL Holdings, Inc. provides automated, cloud-based software for financial operations, including accounts payable, accounts receivable, and spend and expense management, primarily for small and midsize businesses. The platform simplifies, digitizes, and automates back-office financial processes, helping businesses manage cash inflows and outflows more efficiently.
Resilience scores
- Digital Sovereignty: 79
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Billy — Technology — Denmark
- Expensify — Financial Services — United States
- and 26 more
Services catalogue
2 services in catalogue across 1 category; runs on 28 sub-vendors.
- Accounts Payable
- Accounts Receivable
Insights
Last updated 2026-09-13 · revision 1
28 direct vendors, 262 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- Sweden: 1
- India: 1
Subvendors by controlling owner country (sample)
- France: 10
- Australia: 2
- Netherlands: 4
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Bill.com exhibits high migration readiness primarily due to its highly modern and cloud-native technology stack. The extensive use of Amazon Web Services (AWS), containerization with Kubernetes and Docker, and a likely microservices architecture (implied by Kafka, Kubernetes) provides significant flexibility and portability. The presence of a robust BILL API Platform further facilitates integration and potential re-platforming efforts. The absence of specified data residency requirements is also a positive, as it removes a common hurdle for cloud migrations. However, the assessment is hampered by the lack of data on Bill.com's financial stability (revenue concentration, growth history), which is crucial for determining the capacity to fund a significant migration effort. While vendor geographic diversity is present, the "Total Vendors: 0" data point is contradictory and the actual number of vendors and associated lock-in risks remain unknown, making it difficult to fully assess potential dependencies and complexities in a migration scenario. The specific regulatory environment is also not detailed, which could introduce unforeseen compliance challenges during migration.
Compliance
12 in-scope frameworks identified; showing 3.
GLBA — Compliant
BILL is a licensed money transmitter and financial services company subject to GLBA as a financial institution under the FTC's jurisdiction. GLBA requires financial institutions to protect the security and confidentiality of customer financial information. The risk is Medium because: (1) BILL processes highly sensitive financial data (bank account numbers, routing numbers, SSNs, financial statements) for 500K+ businesses; (2) GLBA Safeguards Rule (updated 2023) requires a comprehensive written information security program; (3) A data breach involving financial data could trigger significant regulatory and reputational consequences; (4) BILL's SOC 2 Type II and PCI DSS Level 1 certifications provide strong evidence of GLBA-aligned controls, but no specific GLBA compliance audit is publicly disclosed.
Evidence: https://www.bill.com/privacy, https://www.bill.com/privacy/consumer, https://www.bill.com/product/security
BSA — Compliant
BILL is a licensed money transmitter in all 50 US states plus DC, Puerto Rico, and US Virgin Islands, and is registered with FINTRAC in Canada. As a money services business (MSB), BILL is subject to BSA/AML requirements enforced by FinCEN. BILL explicitly states it has 'adopted an Anti-Money Laundering (AML)/Office of Foreign Assets Control (OFAC) Program.' The risk is Medium because: (1) Money transmitters face heightened AML scrutiny from FinCEN; (2) BILL processes $345B+ in annual payment volume, creating significant AML exposure; (3) BSA/AML violations can result in substantial civil and criminal penalties; (4) The fintech sector has faced increased FinCEN enforcement in recent years. The risk is not High because BILL has explicitly implemented an AML/OFAC program and maintains state-by-state money transmitter licenses.
Evidence: https://www.bill.com/legal/authorizations, https://www.bill.com/product/security, https://www.bill.com/privacy
CPRA — Compliant
BILL is headquartered in San Jose, California and explicitly addresses CCPA/CPRA compliance in its Privacy Notice. BILL provides a California Notice at Collection, a US State Supplemental Privacy Notice, and a 'Do Not Sell or Share My Personal Information' opt-out mechanism. As a California-based company with revenues exceeding $25M annually (BILL's annual revenue exceeds $1B), CCPA/CPRA applies. The risk is Low because: (1) BILL has implemented all required CCPA/CPRA disclosures and mechanisms; (2) BILL explicitly states it does not sell personal information for third-party marketing without consent; (3) BILL provides opt-out mechanisms for targeted advertising; (4) BILL has a dedicated Privacy Officer and privacy contact.
Evidence: https://www.bill.com/privacy, https://www.bill.com/privacy/us-supplemental, https://www.bill.com/privacy/do-not-sell-my-personal-information
Financials
Three-year financials
- 2026: revenue USD 1.65B, EBIT USD -73.4M, equity USD 3.53B
- 2025: revenue USD 1.46B, EBIT USD -80.6M, equity USD 3.91B
- 2024: revenue USD 1.29B, EBIT USD -174M, equity USD 4.13B
Financial Resilience Score: 7/10
BILL Holdings demonstrates solid financial resilience despite ongoing GAAP unprofitability. The company generates highly recurring revenue from subscription and transaction fees tied to SMB payment volumes, producing hundreds of millions in non-GAAP operating income and free cash flow annually. It holds a net cash positive balance sheet with approximately $1.5-2B in corporate cash and marketable securities against partially repurchased convertible notes, providing significant liquidity cushion. The business benefits from strong network effects through 9,500+ accounting firm partnerships and embedded relationships with top US banks (BofA, JPMorgan). Diversified monetization streams across AP subscriptions, transaction fees, Divvy card interchange, FX cross-border spread, and float income (~$100M+ annually on $3B+ customer funds) reduce single-line dependency risk. However, GAAP operating losses persist due to heavy stock-based compensation (~20-25% of revenue), and revenue growth has decelerated sharply from >60% in FY23 to 12% in FY25. The SMB customer base is cyclically exposed, and float revenue is highly sensitive to interest rate cycles. Competitive intensity from Intuit, Ramp, Brex, Melio, and Tipalti continues to pressure the market position.
Key strengths: Highly recurring subscription and transaction revenue, Net cash positive balance sheet with $1.5-2B in corporate cash, Strong distribution via 9,500+ accounting firm partners and top US banks, Diversified monetization across AP, AR, Divvy, FX, and float income, $3B+ customer funds generating $100M+ annual float income, Positive non-GAAP operating income and free cash flow, Shift toward profitable growth with cost discipline and buybacks
Risk factors: GAAP unprofitability driven by heavy stock-based compensation (~20-25% of revenue), Revenue growth deceleration from >60% (FY23) to 12% (FY25), SMB customer base cyclicality and macroeconomic exposure, Intense competition from Intuit, Ramp, Brex, Melio, Tipalti, Coupa, Interest rate sensitivity of float revenue, Card interchange regulation risk on Divvy business, Customer concentration in financial-institution channel (BofA, JPMorgan)
Revenue by geography
- United States: 95%
- International: 5%
Revenue by product/service
- Transaction fees (AP, FX, Divvy interchange): 77%
- Subscription fees: 16%
- Interest on funds held for customers: 7%
Workforce by country
- United States: 2200
- Poland: 300
- Australia: 150
- Other: 50
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.