Security and privacy by design
tallyvero is designed so financial reconciliation data remains in your browser. Files are parsed in memory and no upload endpoint is provided. Closing or refreshing the page clears the working reconciliation state.
Controls
Production deployment requires HTTPS, restrictive security headers, limited request bodies, schema validation, rate limits, redacted logs and short raw-event retention. We do not use session replay, ad trackers, third-party fonts or third-party error monitoring.
Your part
Use a supported, updated browser and a trusted device. Review reconciliation exceptions before changing accounting records. For a security report, email info@tallyvero.com without attaching financial files.