Skip to content
Tallyn

Security

How your data is handled

Tallyn is a developer tool, and developers ask the right questions about where their content goes. Here are the answers, in plain terms.
01

What we store

Your account: your name, email, an optional company, and a password stored only as a scrypt hash, never in plain text. If you sign in with Google or GitHub we store the email that provider gives us and no password.

Your audits: the cleaned markup you audited, the issues Tallyn found, and the drafted fixes, tied to your account so you can open them again and re-check.

02

How model providers are used

To produce an audit, the page markup is sent to a model provider over an encrypted connection. It is used to generate your report and for nothing else, under agreements that prohibit the provider from training on that traffic.

We do not sell your content, we do not use it to train any model of our own, and we route across providers through one interface, so which provider handles a request is a configuration choice, never a change to this promise.

03

Who can see your audits

You can. Audits are scoped to your account, and a report page checks that the audit belongs to the signed-in user before it renders. On Business plans, seats in your organization share an audit library by design.

Our team does not read your audits as a matter of course. We access stored content only when you ask us to for support, or where the law requires it.

04

Encryption and access

  • In transit: TLS on every connection to the site and to model providers.
  • At rest: the database is encrypted at rest by our hosting provider.
  • Access: production access is limited to the founders and is logged.
  • Secrets: API keys live only in server environment variables, never in the code or the browser.
05

Deleting your data

You can delete any single audit, or your whole account, from Settings. Deleting an account removes your profile and every audit and stored snippet with it, immediately, and it cannot be undone.

If you would rather we did it, email security@tallynaccess.com and we will remove your account the same business day.

06

Reporting a vulnerability

We take reports seriously and will not take legal action against good-faith research. Email security@tallynaccess.com with the details and steps to reproduce, and we will acknowledge within one business day.