Security information
Pilot-stage notice: This page records the intended product boundary. A formal security review and penetration test are required before broad rollout.
Separated customer environments
The approved pilot architecture gives each customer a separate deployment, database and integration credentials. The public website and synthetic demo do not connect to customer environments.
Limited provider access
Practices authorise their own Splose and Xero connections. Tally restricts connector operations to the reporting datasets approved for the service and blocks patient endpoints at the connector boundary.
Access and audit
Application access is role-scoped. Security-sensitive actions and published calculation changes are recorded for review.
Report a concern
Send security concerns to hello@tally.com.au. Do not include patient data or credentials.