Security
Last updated 7 October 2026
AnalyseAI Tally Assistant reads your accounts. Here is exactly how it reaches your Tally, what it can and can't do there, and what happens to your data. Questions: hello@tegain.com.
Nothing on your network is opened
- A small AnalyseAI connector runs on the PC where TallyPrime is open. It dials out to AnalyseAI over an encrypted connection (TLS), the way a browser does. No port is opened in your firewall, there is no port forwarding or VPN, and Tally itself never faces the internet.
- The connector talks to Tally only on that PC. It can't be pointed at other computers on your network without an administrator of that PC.
- Each connector has its own secret, stored only as a hash on our side. A new PC can't take over from your working one until an admin of your account chooses it.
It can only read, never change your books
- Every request to Tally must match a short, fixed list of read-only report and list exports. AnalyseAI's servers check each request against that list before sending it, and the connector checks it again on your PC before Tally sees it.
- Anything else is refused: imports, new or changed vouchers or masters, Tally functions and actions, reading or writing files, or reaching other machines.
- This holds even if our servers were misused: the connector on your PC keeps its own copy of the list and refuses whatever isn't on it.
You stay in control on your PC
- The connector app shows every request AnalyseAI made to your Tally (which report, which company, when, and whether it was answered or refused), from its own record on your PC.
- Pause stops all requests at once, until someone at the PC resumes. Uninstalling the connector ends access completely.
- Linking the PC to an account, unlinking it, or changing where Tally is needs a Windows administrator on that PC.
- The connector runs as its own low-privilege Windows service account, not as the system.
Your data
- Each business's data is kept separate; every request is checked against the organisation it belongs to.
- Data travels encrypted (TLS). Report files are stored privately and only ever reach a signed-in person of your business.
- Report files (PDF, Excel) and the figures in them are deleted 90 days after the report was run. Chats stay until you delete them. Deleting your organisation removes everything at once; backups roll over within 8 weeks.
- You choose which companies and reports each user may ask about, on the web or WhatsApp. Team members who sign in to the console can see your organisation's chats and reports, so add only people you trust with them.
The AI
- The AI sees your question and the figures needed to answer it, not your whole books. It can only ask for the reports your people are allowed to run; that is enforced by our code, not by the AI.
- Answers in the app never load outside images or links on their own, so text inside your Tally data can't send your figures anywhere.
- When requests go through OpenRouter, only model providers that neither store nor train on the data are used.
Accounts and sign-in
- Sign-in is by one-time email code: no passwords to leak. Wrong codes are limited per address, and a code works once.
- The long-lived sign-in token is kept in a secure cookie the page can't read; short-lived tokens stay in memory.
- Owners and admins manage setup; changes are recorded in your organisation's activity log.
Reporting a problem
If you find a security issue, email hello@tegain.com with "Security" in the subject. We reply within two business days, and we won't take action against good-faith research that avoids other people's data.