Terms and legals
Tallyfy is very strongly positioned when it comes to compliance, legal, security and privacy:
- SOC 2 Type 2 attested
- HSTS compliant - this is very important even though other vendors don’t talk about it because it prevents common man-in-the-middle attacks. Our domain - tallyfy.com is pre-loaded as secure in common browsers.
- BIMI compliant - which is an email standard that ensures very strong compliance to brand and recognition, preventing phishing and much more.
- Able to sign a custom DPA for EU, DPA or specific US states
- GDPR compliant via our Privacy Shield and DPF attestation
- Able to sign contracts for customized enterprise requirements
- We offer free SSO (Single Sign On) to all customers. Security should not cost extra.
- Data is encrypted in transit and at rest
- Data is logically separated in our multi-tenant cloud hosting on us-west-2 on Amazon Web Services
- Every API request goes through a custom Cloudflare Worker and a WAF (Web Application Firewall)
- We block countries under US trade sanctions
- Requests from Tor browsers are dropped and never accepted
- Rate limiting runs on the edge at any scale
- We can offer custom insurance coverage for enterprises
Related articles
Terms & legals > Tallyfy's privacy policy
Tallyfy prioritizes information security and provides detailed privacy policy and IT documentation for users' assurance.
Terms & legals > Country restrictions
Tallyfy restricts access to its product in certain countries for safety and operational reasons.
Tracking > Protect Sensitive Data
The recommendation emphasizes the importance of securely collecting and storing sensitive data, accessible only to authorized personnel, to maintain customer trust and confidentiality.
Pro > Miscellaneous
Tallyfy offers comprehensive support, legal information, and resources to assist users with their needs and ensure compliance.