Security and your clients’ data
What a CA or a firm’s IT person asks before installing ComplyEaze Bridge next to client books, in one place. Each answer repeats what the Questions page, the Privacy Policy, the security policy and the security and privacy notes already say. Where this page and those documents differ, those documents apply.
What stays on your computer
ComplyEaze Bridge keeps a log of every call: the tool, the time, the company’s Tally identifier, fingerprints of the question and the answer, how many rows came back, and the last requests it sent to Tally. The log is designed to hold no figures, names or narrations, though sizes in it can hint at the length of a name.
It also keeps copies of the vouchers it prepared or posted, the proof of what Tally read back, every row of a bank statement you asked it to read, and a small record, with your operating-system account name, when you record a review of a posted voucher. The copies hold dates, amounts and narrations. None of these files is encrypted. ComplyEaze Bridge does not delete or trim any of them, and removing the extension may leave them. Section 7 of the Privacy Policy says where they are and how to archive them.
What reaches your AI provider
Your AI provider (Anthropic, if you use Claude) receives whatever the assistant reads, as part of the chat: company names, party names, amounts and, when it asks for them, details such as PAN, GSTIN and bank account numbers. Claude Desktop may also keep its own record of the conversation and results on your computer.
The extension’s “Response redaction” setting (off by default) can shorten party and ledger names or drop narrations. Neither choice hides amounts, company names, or PAN and GSTIN numbers. Masking leaves a name written inside a narration or reference as it is; dropping narrations removes narrations but not references. How long the provider keeps what it receives, whether it trains on it, and where it is processed (which may be outside India) depend on your plan and the provider’s own terms.
What reaches ComplyEaze
Through ComplyEaze Bridge on your computer, we do not receive your Tally data, your conversations with your AI assistant, the files it keeps on your computer, or usage statistics, crash reports or device identifiers (section 4 of the Privacy Policy). We found no analytics, usage tracking, crash reporting or automatic update check in it. That comes from our reading of the published code and our own checks; it has not been independently audited.
Posting waits for your approval
Posting is off in a new install; if you upgraded from an earlier version, check the setting. Reading, checking ledger names, reading a bank statement and preparing a voucher file write nothing to Tally.
With posting on, it can post one Journal, Payment, Receipt or Contra at a time, and only after you approve that voucher in a separate window. No ComplyEaze Bridge tool can approve it for you, but software that controls your screen could click the window, so do not let it. An approval is used once and stays valid for at most 15 minutes after you give it.
After each post it reads the voucher back and reports what it found. It compares some details, not every one, and a match does not mean the entry is correct. Two known limits can send a post to the wrong place: a company renamed to, or loaded under, the target’s name just after the last check, and a ledger renamed and replaced in the same moment. It may not be able to say where the voucher went. ComplyEaze Bridge has no tool to delete or undo a posted voucher; you correct it in Tally. The README gives these limits in full.
The connection to Tally
ComplyEaze Bridge connects to Tally only at an address that means “this computer”: localhost, 127.0.0.1 (or any 127.x.x.x) and ::1. It does not use a proxy or follow redirects. If you or your IT support forward that address somewhere else, its requests go wherever you forwarded them.
Tally’s own gateway is a separate question. In one test by a maintainer on TallyPrime 7.1 (not recorded in the repository), a second computer on the same network opened the Tally computer’s address and port and got Tally’s status answer with no password asked. What keeps other computers out is the firewall of the computer that runs Tally, not Tally itself. We did not test what else the gateway shows. Ask whoever looks after your computers to confirm that the firewall does not allow incoming connections to Tally’s port.
Reporting a vulnerability
Please do not report a vulnerability in a public issue. Report it privately, through GitHub private vulnerability reporting, or by email to security@complyeaze.com. We aim to acknowledge a report within seven days. If we fix a security issue, the fix will be in a new release; we are not obliged to make one. Published advisories are listed in the security policy.
What has not been done yet
- It is not yet code-signed or notarised: Apple and Microsoft have not certified it as coming from us, so your computer may warn you before opening it. Compare each download with the
.sha256file on the same release before opening it. - No independent security audit has been done. The source code is public and the project runs its own checks, but that is not an external review.
- Not yet run by us in a controlled test: posting with a published package against a live TallyPrime; each way of declining in the Windows approval window (one was tried); the tools answering through Claude Desktop on macOS after the Terms are accepted; posting on TallyPrime Education; posting on TallyPrime Gold with its approval step recorded. The README lists what has been run.
- Not measured: a network capture of the running extension on Windows or a Mac; the permissions its data folder ends up with on Windows (on a Mac, ComplyEaze Bridge restricts its folder to your user account through file permissions); and whether PDFium, the PDF library it uses only to read a bank statement you name, opens any network connection or file other than that PDF.
The security and privacy notes give each answer in more detail, with what was measured and what was not. The README lists each run against Tally.