The systems we verify hold sensitive records. We designed Tallystone so that working with us adds as little risk surface as possible — and so that no client's data is ever within reach of another.
Tallystone never connects into your production environment. You export two snapshots — a baseline and a target — and send only those. We work entirely from the data you choose to hand over. There is no standing connection to compromise and no live system for us to reach.
Every client's extracts, screenshots and findings are separated from every other client's — enforced in more than one layer, so a single mistake can't cross the boundary. Clients cannot see one another. There is no shared view in which one company's data appears alongside another's.
Data is delivered over an encrypted channel and stored encrypted. Access to stored artifacts is authenticated and logged, and scoped to the client that owns them.
We ask for the data needed to compare two versions and nothing more. Where your extracts can be reduced — masked identifiers, only the tables in scope — we would rather receive less. Snapshots are retained only as long as your project needs them and are removed on request.
Tallystone proposes; your people decide. AI classifies differences to save your reviewers time, but accepting a change or confirming a regression is always a human action, recorded against the finding. You keep a full, auditable trail of who decided what.
Regulated buyers usually do. We're happy to work through yours — get in touch and we'll walk through our data handling in the detail your process requires.