Security & privacy
Built using security and privacy best practices. Here is exactly how your data is handled.
Your data is isolated
Every organization's data is separated at the database level using row-level security, not just application-level filtering. Other organizations can never read your data, and you can never read theirs.
Private file storage
Uploaded files are stored in private, organization-scoped storage. Files are never exposed through unrestricted public URLs.
What the AI sees
The AI summary feature only ever receives aggregated KPIs, detected trends, and structured findings that your data already produced — never your raw uploaded file, and never used to train any model.
Financial calculations never touch AI
Every KPI — revenue, orders, margins — is computed by deterministic application code. The AI's role is limited to explaining numbers that have already been calculated and verified.
You control your data
You can delete a dataset at any time. Deleting a dataset removes its normalized records, analytics, AI reports, and the original stored file.
Compliance status
Tahlely AI is built using security and privacy best practices. We do not currently hold formal certifications such as SOC 2, ISO 27001, GDPR, or PCI compliance.