Security information

Pilot-stage notice: This page records the intended product boundary. A formal security review and penetration test are required before broad rollout.

Separated customer environments

The approved pilot architecture gives each customer a separate deployment, database and integration credentials. The public website and synthetic demo do not connect to customer environments.

Limited provider access

Practices authorise their own Splose and Xero connections. Tally restricts connector operations to the reporting datasets approved for the service and blocks patient endpoints at the connector boundary.

Access and audit

Application access is role-scoped. Security-sensitive actions and published calculation changes are recorded for review.

Report a concern

Send security concerns to hello@tally.com.au. Do not include patient data or credentials.