Docs › Security and compliance
Data protection in brief
Where data lives, what leaves, and what never does.
The full description is on the Security page. In short:
- Residency. Every identifiable record lives on one server in South Africa that the practice controls or that Tallify operates for that practice alone.
- Local first. Reading documents, extracting facts and search embeddings run on models on that server. The file and the identity never leave.
- De-identified drafting. Only the drafting step uses an external model. Before it, names, ID numbers, dates of birth, contact details and addresses are removed from the structured facts and scrubbed from free text, for the client and the spouse. The model sees "the client, 47, two dependants", never a name. The name goes back in on the practice server.
- No training. The external model provider's API terms exclude training on customer data.
- Approval gate. Nothing is sent to a client and nothing is filed without a named person.
- Audit. Every change, sign-in and communication is logged.
- Tested. The evaluation suite asserts that no identifier leaks into the de-identified box, and the practice can run it on demand.
Updated 2026-09-10. Questions: michael@tallify.co.za.