Home / Security
Security

Security & data handling

Factual controls only. We claim no certifications we do not hold.

The short version

tallywire holds business and service data only: no consumer profiles, no reviewer identities, no payment data, no special-category data. That minimization is the largest part of our security posture.

Website

The site is static and served over TLS with HSTS from a CDN (Netlify). It sets no tracking cookies, runs a strict Content-Security-Policy, and loads only the third parties named in the privacy notice.

Data pipeline and storage

Collection runs in isolated per-source drivers with no third-party code dependencies in the ingest path. The dataset lives in a managed Postgres service with key-based access; credentials are held by the founder, rotated on suspicion, and never shipped to the website. Backups are managed by the database provider.

Deliveries

Market Files are delivered directly to the buyer (private link or email attachment); API keys are issued per organization and can be revoked at any time.

Subprocessors

Netlify (hosting), Supabase (database), Formspree (forms), Crisp (chat), Simple Analytics (cookieless analytics), plus our email provider.

Reporting a vulnerability

Email hello@tallywire.io. You get a reply from the founder within one business day.

tallywire · the local-service supply feedSecurity
tallywire is not affiliated with or endorsed by the platforms shown. Platform names and marks belong to their respective owners; data is observed from public listings.