Account access
Email confirmation is required. Optional TOTP multi-factor authentication adds an authenticator-app code at sign-in.
Security
Tallyo combines confirmed accounts, optional MFA, database access rules and server-side sensitive operations. No system can remove every risk, so this page explains both controls and limitations.
Email confirmation is required. Optional TOTP multi-factor authentication adds an authenticator-app code at sign-in.
Supabase Row Level Security restricts database access so each signed-in account can access its own workspace records.
Payment amounts, dates and notes remain connected to the relevant invoice and account. Customer card payments are available after you connect your own Stripe account. Stripe handles card processing and payouts directly with your business; Stripe fees apply and Tallyo does not add an application fee.
Private email, payment and service credentials stay in server-side provider environments rather than browser code.
The app uses a Content Security Policy, integrity-checked pinned libraries and a self-hosted stylesheet.
Tallyo provides device and all-device sign-out controls, optional backup authenticators and one-time recovery-code support.
What these controls do not mean
Account guide
Follow the focused guide to authenticator-app MFA, recovery codes and the right sign-out choice.
Ready when you are
Create professional documents, track payments and spend less time repeating the same setup.