Nobody else can read your books.Not even us.
We are asking to read the computer where your accounts live. That is a fair thing to be careful about. So here is exactly what leaves your computer, what we can see, and what we can never do. In plain language, no jargon.
One locked file. Nothing else.
A small program sits on your Windows computer next to TallyPrime. Every few hours it reads your company, locks it with a passphrase only you know, and sends one file to our storage. That locked file is all that ever leaves. No live connection to your computer, no one logging in, no window left open for anyone to reach through.
Locked on your computer
The books are checked and locked with your passphrase before anything is sent.
One file goes out
The locked file, and nothing else, travels to our storage every few hours.
Opens with your passphrase
Your phone downloads that one file and opens it, then works offline.
Nothing. We hold a locked file we cannot open.
The file is locked on your computer before it is sent, using your passphrase. We never receive that passphrase. So the file sitting on our storage is, to us, a block of meaningless characters. We cannot turn it back into your ledgers, your balances, your customers or your bank figures, because the one thing that would open it never reaches us.
What we store
A locked file, and a note of when it was made. That is the whole of it.
What a stolen server gives
The same locked characters, with no key held anywhere near them. Useless without your passphrase.
Who else can read it
Nobody. Not us, not the company that hosts the storage. The lock is the same for everyone who is not you.
Two things this product is built so it cannot do.
It cannot change your books.
The program only ever reads from TallyPrime. It has no ability to create, edit or delete an entry, that path does not exist in the program at all. Using this cannot damage your accounts, because it can only ever ask Tally to hand a copy out, never to write anything back.
It cannot recover your passphrase.
We never hold your passphrase, so there is no reset button we could press and no copy we could hand to anyone, not to a stranger who asks, and not to us. This is the same fact that keeps your books safe, seen from the other side.
The file is on shared cloud storage. The key is in your head.
The locked file sits on well-known cloud storage run by a large hosting company. They keep the file safe and available, but they hold the same locked characters we do, and no key either. The key is your passphrase, and it is only ever in two places.
| The thing | Where it lives |
|---|---|
| Your passphrase, the key | On your own computer, and in your memory. It is never sent over the internet and never stored on any server. |
| The locked file, the books | On cloud storage. Also copied onto each phone you open it on, where your passphrase opens it. |
| Your original books | In TallyPrime on your computer, exactly as they always were. This product never touches them. |
Keeping the locked file and the key in different places is the whole idea. Whoever holds the file cannot read it, and the only person who holds the key is you. A break-in at the storage company would hand the thief a locked file and nothing to open it with.
We cannot get it back for you. Here is why we built it that way.
If you forget your passphrase, nobody can recover the locked file. Not us, not the hosting company, not a court order. There is no back door, because a back door is exactly what would let someone else in too.
This sounds alarming, so read the next line carefully: nothing is lost from your actual books. Your accounts live in TallyPrime on your computer, untouched. If a passphrase is forgotten, you simply set a new one on the computer and open the app again with it. The only thing that becomes unreadable is the old locked copy on the server, and that copy is rebuilt from Tally at the next sync anyway.
Write your passphrase down and keep it somewhere safe, the way you would a key to the shop. The app can suggest an easy to type one made of ordinary words, like marble-ridge-copper-lantern, harder to guess than a short password, and far easier to type on a phone.
For your IT person or your CA.
If you are not technical, you can stop here, the plain language part above is the whole story. This section is for the person who will ask.
Encryption
The snapshot is encrypted on the computer with AES-256-GCM before it leaves. The key is derived from the passphrase with PBKDF2-HMAC-SHA256 at 310,000 iterations, with a fresh random salt and nonce on every push.
Zero-knowledge server
The server that receives the file never decrypts it, never parses it, and holds no key. It is a plain store for encrypted blocks. A breach of that platform yields ciphertext and nothing else.
Read-only against Tally
The program speaks to TallyPrime using export requests only. Every outgoing request is checked at a single point in the code and refused if it is anything but a read. There is no write path.
No inbound connection
Your computer only makes outgoing requests. No port is opened on it, and nothing on the internet can start a connection to it. There is no tunnel and no remote-desktop tool involved.
Credentials at rest
On the computer, the sync token and passphrase are stored using Windows DPAPI, tied to the Windows user account. Copying that file to another machine yields nothing usable.
Tamper-evident
The lock includes a built-in check, so any change to the file, even a single altered character, makes it fail to open rather than quietly showing a wrong figure.
Sharing part of the books with staff
You can give your accountant, a salesperson or a collections clerk a limited view. This is not a hidden menu, the figures they are not entitled to are never sent to their phone at all. Their copy is locked separately, with its own passphrase, and contains only their part of the books. You can withdraw any view at any time, and it stops working at the next refresh, without changing your own passphrase.
The figures on your phone are a snapshot from the last sync, not a continuous feed, every screen shows how old they are, and warns you when they are more than a few hours old. And anything you choose to share out, a customer statement over WhatsApp, a report exported to a spreadsheet, leaves the locked copy by design, that is the one feature that does, which is why it is off until you turn it on.
Still have a question about safety?
Ask it before you buy. A real person answers on WhatsApp during support hours.