Say you type “What did Nevrika Agro Foods pay us in March?” in Claude Desktop, with ComplyEaze Bridge installed. Six things happen. In the sixth, the answer from your client’s books leaves your computer for your AI provider, as part of the conversation.
Release 0.4.2 is out. This post describes release 0.4.1. If you install 0.4.2:
- Remove the older extension in Claude Desktop first: 0.4.2 installs beside an older one instead of replacing it (seen with 0.4.1 on a Mac and expected for earlier versions; not tried on Windows). Keep ComplyEaze Bridge’s data folder, which both versions use.
- Enter your settings again, including the Terms setting, which every tool needs. Posting starts off, and Response redaction starts at none, so set it again if you had shortened or masked names.
- Its posts no longer tag the narration, and it matches a posted voucher another way. Check what it posted with
verify_import, nevervoucher_presence, before entering anything again by hand. The one-voucher post the extension makes has not been run live with this matching. From the first post 0.4.2 sends to Tally, even one Tally refuses or never answers, do not run 0.4.1 or earlier on that computer: they stop preparing, posting and checking vouchers. - If you asked 0.4.1 or earlier to read a ledger, such as its movement or vouchers, by a name that differed from its spelling by a symbol, an accent or words run together, the figures may be for a different ledger with the same letters and digits. Ask again with 0.4.2.
The changelog has the rest.
ComplyEaze Bridge is an open-source extension for Claude Desktop that lets Claude read the TallyPrime books open on your own computer, so you can ask questions of them in plain words. What it reads, and its limits, are in the notes at the end.
Follow one question
Point at, or tab to, a step to see it in the picture.
- You ask Claude Desktop. Your question goes to your provider as part of the conversation.
- Claude calls a tool in ComplyEaze Bridge, which runs on your computer.
- The tool asks TallyPrime through Tally’s own connection, at an address that means “this computer”.
- Tally answers, and a line goes into a log on your computer.
- The answer goes to Claude Desktop. It holds the party’s name and the amount.
- Claude Desktop sends it to your AI provider, as part of the conversation. This is where what it read from the books leaves the computer.
We know of one other route: a flaw in releases 0.3.0 and 0.4.0 that could send your Windows network sign-in response to another computer. No Tally data is sent. Release 0.4.1 refuses network paths, but a drive letter mapped to a network share, a link or junction partway along a path, and on a Mac a mounted network volume can still pass; the notes at the end say more. We have captured no network traffic, so there may be other routes.
ComplyEaze Bridge cannot be pointed at a Tally on another machine, and it cannot tell whether you have forwarded Tally’s address on this computer elsewhere, so do not forward it across the internet.
Does any of it reach us?
We do not receive your Tally data through ComplyEaze Bridge, and our Privacy Policy says so. We looked for an upload in the code and found none. We read release 0.4.0 and checked the 0.4.1 changes to network destinations. That was reading the source. We have not measured the running program, and nobody outside has audited it.
What your provider can receive
Depending on what Claude asks for, what reaches your provider can include:
- company, ledger and party names
- vouchers with dates, amounts, narrations and GSTINs
- outstanding bills
- the trial balance and other statements
- PAN, bank account numbers and contact details, when it asks for them
- the contents of a bank-statement PDF you ask it to read
- file locations that usually include your computer user name
Whether your provider keeps this, trains on it or processes it elsewhere depends on the provider, your plan and your settings. We do not know yours.
Ask your provider three things
- Is it kept?
- Is it used for training?
- Where is it processed?
For Claude, start with Anthropic’s Privacy Policy (anthropic.com/legal/privacy). It does not apply to content Anthropic processes on behalf of customers of its business offerings, such as Enterprise accounts.
Party and ledger names can be shortened; amounts cannot
ComplyEaze Bridge has one masking setting, “Response redaction”. It can shorten party and ledger names to their first two and last two characters, or it can remove narrations, but not both. Neither makes the data anonymous. Amounts, company names, GSTINs and PAN numbers are never masked. Out of the box, nothing is masked.
Change the setting and see a simplified view of what your AI provider receives. A Receipt from the site’s synthetic demo book; the narration was added for this example.
- Company
- Demo Traders Pvt Ltd (synthetic)never masked
- Party
- Nevrika Agro FoodsNe…ds
- Ledger lines
- Dr Example Bank LtdEx…td₹1,24,600.00never maskedCr Nevrika Agro FoodsNe…ds₹1,24,600.00never masked
- Narration
- Received from Nevrika Agro Foods against bill 112removed from the answerA name written inside a narration is not shortened.
Out of the box, nothing is masked.
Party and ledger names are shortened to their first two and last two characters, by the extension’s own rule; a name of four characters or fewer becomes “…”. The data is not anonymous.
Narrations are removed, but names stay in full. You cannot choose both.
“Response redaction” is a text field in the extension’s settings: you type one of the three values shown under the buttons exactly, and any other value stops the extension from starting.
Changed by the setting. Not masked by either setting, including amounts, company names, GSTINs, PAN numbers, references and contact details.
It shortens names only in what ComplyEaze Bridge returns. A name you type, or that Claude asks you to type, goes to your provider in full.
Your client’s authority
Our Terms and Privacy Policy put one more thing on you. You need each client’s authority to access their books with ComplyEaze Bridge and to share their data with your AI provider, and you must give any notice or get any consent that the law or your engagement requires. Your duties of confidentiality still apply, and so does the Digital Personal Data Protection Act, 2023, where it applies (Terms of Use, section 8).
What stays on your computer
ComplyEaze Bridge keeps several files on your computer; three kinds matter here. One is designed to hold no amounts or names; two hold them in full. Claude Desktop may also keep its own records of conversations and results on your computer.
-
The log
Among other things: the time, the tool, Tally’s internal code for the company, and short codes (“fingerprints”) of the request and the result. Sizes can hint at a name’s length, so treat it as confidential.
No amounts or names, by design -
The import journal and import files
The vouchers it prepared or posted, what Tally read back, and review records with your computer user name.
Amounts and names, unmasked -
Bank-statement proposals
Voucher proposals from bank statements, including the last four digits of the account number.
Amounts and names, unmasked
None of it is deleted automatically, and removing the extension may leave it behind. Do not simply delete the folder: ComplyEaze Bridge uses it to avoid sending the same batch twice, so the Privacy Policy tells you to check Tally and then archive it in an encrypted archive. Administrators and backup software on the computer may be able to read these files, and on Windows they take the folder’s normal permissions.
What it can do to your books
Reading does not write to your books. A large read can still slow Tally, sometimes until Tally is restarted, and that can affect other people on a shared Tally. Reads on very large books can fail or take longer than the assistant waits.
-
Off
Posting is off in a new installation. If you upgraded, check the setting, because an earlier default may still be saved as on.
-
Waits
When it is on, each voucher (Journal, Payment, Receipt or Contra) waits for your approval in a separate window on your computer.
-
You approve
An approval is used once and expires.
-
Tally posts
The tool cannot undo a posted voucher; you correct it in Tally.
-
Read back
After posting it reads the voucher back, and a match does not mean the entry is correct or compliant.
No ComplyEaze Bridge tool lets the assistant approve a post, but software that can control your screen could still click the button, so do not let such software run while a posting is waiting.
A post can land in the wrong place if a company or ledger is renamed, replaced or loaded in Tally at that moment, so leave companies and ledgers alone while a post is waiting. It does not create masters or post sales, purchase, tax or inventory entries.
The run we recorded in the notes at the end was one run of a candidate build of 0.4.0, on one made-up company, and we have not yet run the published 0.4.1 file in Claude Desktop.
Using it on a client’s books: a checklist
Before you start
- Get each client’s authority to use it on their books and to share their data with your AI provider, and give any notice or get any consent that the law or your engagement requires.
- Check what your provider keeps, whether it trains on it, and where it processes it.
- Choose the Response redaction value: none, mask_parties or drop_narration.
- Take a backup, and try a test company first.
- Read the Terms of Use, including section 14 on liability.
- If you have 0.3.0 or 0.4.0, remove it and install 0.4.1 or later. If you upgraded, check the posting setting.
- Use a device password and full-disk encryption.
- Your computer may warn you when you open it: it is still being developed and not yet code-signed.
While you use it
- Check what you get in Tally before you rely on it.
- Before turning posting on, and regularly while it is on, keep current, tested backups.
- Do not forward Tally’s address across the internet.
- Keep statements and password files on the computer’s own disk.
- While a post is waiting, run no software that can control your screen, and leave companies and ledgers alone.
When you stop
- Quit Claude Desktop, check Tally, then move the whole data folder into an encrypted archive (section 7 of the Privacy Policy). Do not simply delete it.
We do not promise support or updates. Nothing here is accounting, tax, audit or legal advice.
Notes for whoever installs it
Network paths in 0.3.0 and 0.4.0, the run we recorded, what it reads and where it runs
Network paths in 0.3.0 and 0.4.0, refused from 0.4.1
In releases 0.3.0 and 0.4.0 the bank-statement tool could be given a Windows network path, meaning a file on another computer. Windows then connects to that computer and may send the signed-in user’s network sign-in response to it. No Tally data is sent. It needed the assistant to be steered into giving such a path (for example by text it has read), your approval of that call or an “always allow” setting, and outbound file-sharing or WebDAV traffic to that computer.
Examples refused from 0.4.1
- A Windows network path, such as
\\computer\share\statement.pdf(a made-up example) - A long-path form, such as
\\?\C:\statements\statement.pdf; use the plain drive path instead
Examples that can still pass
- A drive letter mapped to a network share
- A link or junction partway along a path
- On a Mac, a mounted network volume
Keep statements and password files on the computer’s own disk. If you have 0.3.0 or 0.4.0, remove it and install 0.4.1 or later. ComplyEaze Bridge does not check for updates itself, so look at the releases page now and then. The advisory is linked from our security policy.
What we have run
| Build | A candidate build of 0.4.0 |
|---|---|
| Computer | Windows 11 |
| Claude account | A new account with no paid plan |
| Tally | TallyPrime Silver 7.1, one made-up company |
| Terms setting off | We called a tool; it refused and read nothing |
| Terms setting on | Six tools answered |
| One post declined | Declined in the approval window; nothing was sent to Tally |
| One post approved | Tally took one Journal, and the read-back found it |
What we have not run yet includes the published 0.4.1 file in Claude Desktop, a recorded run for every read, and posting with the published package against a live TallyPrime. The README lists what we ran, on which build, and what we have not.
What it reads, and where it runs
It reads outstanding receivables and payables with ageing, the trial balance, profit and loss, balance sheet, ledger movement, vouchers in a date window, a purchase register and closing stock. Some of these reads refuse a book rather than answer in part, and books with several currencies or many stock items have further limits. It can also check ledger names against your book and prepare Journal, Payment, Receipt and Contra vouchers as a file.
We are still developing it, and it is not yet code-signed, so your computer may warn you before opening it. We publish it for Windows (x64) and Apple Silicon Macs, with TallyPrime on the same computer. On a Mac, TallyPrime runs in a Windows virtual machine, with the connection forwarded locally.
ComplyEaze Bridge is not a product of, or endorsed by, Tally Solutions, Anthropic or ICAI. Email contact@complyeaze.com · Questions and answers · Download and release notes · Terms of Use · Privacy Policy · Security and privacy · Security policy
Read next
Bank statement to Tally vouchers: check the ledger names first
Six steps for password-protected PDF statements from SBI, HDFC and Union Bank of India, built around one check: the ledger names in your mapping against your live book.