Security information

Pilot-stage notice: This page records the intended product boundary. A formal security review and penetration test are required before broad rollout.

Separated customer environments

The pilot architecture is designed to give each customer a separate deployment, database and integration credentials. The public website and synthetic demo do not connect to customer environments.

Limited provider access

Practices authorise their own Splose and Xero connections. Tally is designed to restrict connector operations to the reporting datasets approved for the service and to block patient endpoints at the connector boundary.

Access and audit

Application access is designed to be role-scoped, and security-sensitive actions and published calculation changes are designed to be recorded for review.

Report a concern

Send security concerns to hello@tallyhealth.au. Do not include patient data or credentials.