Trust
Security at Tallify
Your financial data deserves serious protection. Here's how we keep your books, invoices, and client records safe.
Last updated: October 9, 2026
1. Encryption
Data is encrypted in transit with TLS and at rest using industry-standard encryption.
2. Bank connections
Bank feeds use Stripe Financial Connections. Tallify never sees or stores your bank login credentials, and connections are read-only.
3. Payments
Card, Apple Pay, and ACH payments are processed by Stripe, a PCI DSS Level 1 certified provider. Card numbers never touch our servers.
4. Access controls
Access to customer data is limited to authorized staff who need it to provide support or Human Review, and access is logged. Bookkeepers only see the accounts they are assigned to.
5. Client portals
Client magic-link portals use unique, hard-to-guess links that show only that client's invoices and receipts. You can revoke a link at any time.
6. Monitoring & backups
We monitor systems for unusual activity and keep regular backups to protect against data loss.
7. Reporting a vulnerability
Found a security issue? Email security@tallify.ai. We appreciate responsible disclosure and respond promptly.