I can only assume that they defer to the merchant’s URL scheme or maybe some merchants still don’t have SSL.
CCBill’s system has been around for decades. Some elements—like approval/denial URLs or dynamic redirects—are still based on old standards that predate HTTPS being ubiquitous.
You can also double-check your CCBill Subaccount Admin panel.
Go to: Subaccount Admin > Approval URL / Denial URL
Make sure those links use
https://.
If using Webhooks or postbacks then look under Advanced Settings or consult with their tech support to force secure callback URLs.