Security information
Pilot-stage notice: This page records the intended product boundary. A formal security review and penetration test are required before broad rollout.
Separated customer environments
The pilot architecture is designed to give each customer a separate deployment, database and integration credentials. The public website and synthetic demo do not connect to customer environments.
Limited provider access
Practices authorise their own Splose and Xero connections. Tally is designed to restrict connector operations to the reporting datasets approved for the service and to block patient endpoints at the connector boundary.
Access and audit
Application access is designed to be role-scoped, and security-sensitive actions and published calculation changes are designed to be recorded for review.
Report a concern
Send security concerns to hello@tallyhealth.au. Do not include patient data or credentials.