Security

Practical controls, described honestly.

Tallyo combines confirmed accounts, optional MFA, database access rules and server-side sensitive operations. No system can remove every risk, so this page explains both controls and limitations.

Account access

Email confirmation is required. Optional TOTP multi-factor authentication adds an authenticator-app code at sign-in.

Workspace separation

Supabase Row Level Security restricts database access so each signed-in account can access its own workspace records.

Payment records

Payment amounts, dates and notes remain connected to the relevant invoice and account. Customer card payments are available after you connect your own Stripe account. Stripe handles card processing and payouts directly with your business; Stripe fees apply and Tallyo does not add an application fee.

Server-side secrets

Private email, payment and service credentials stay in server-side provider environments rather than browser code.

Browser protections

The app uses a Content Security Policy, integrity-checked pinned libraries and a self-hosted stylesheet.

Recovery and sessions

Tallyo provides device and all-device sign-out controls, optional backup authenticators and one-time recovery-code support.

What these controls do not mean

Security is an ongoing practice, not a badge.

  • Tallyo does not claim to be fully secure or certified.
  • Activity history is useful, but it is not a tamper-proof compliance audit log.
  • Authenticated business records require an internet connection.
  • Users remain responsible for protecting downloaded files and their devices.

Account guide

Set up protection in plain language.

Follow the focused guide to authenticator-app MFA, recovery codes and the right sign-out choice.

Ready when you are

Bring your invoicing work into one clear workspace.

Create professional documents, track payments and spend less time repeating the same setup.