Tallyhook
Live demoFeaturesDocsPricingDocsPricingStart free
Trust

Security

Last updated September 19, 2026

The short version

Tallyhook is a small, self-funded product. We don't have a SOC2 report or a dedicated security team, and we say that plainly rather than let you assume otherwise — no other tool in this category has one either as of this writing. What we do have: real, specific practices below, and an open-source collector you can read yourself in five minutes rather than take our word for.

What never leaves your machine

Code, diffs, tool output, environment variables and secrets, and full prompt or response text are never uploaded, full stop — not "encrypted before upload," not "anonymized," not sent at all. The collector reads the agents' local log files only to count tokens and pick out the metadata listed in the Privacy Policy. The collector is open source (MIT) and one dependency-free file (GitHub, npm); you can read exactly what it does before you run it. See the Privacy Policy for the full list of what metadata is uploaded.

In transit and at rest

Every connection to tallyhook.dev is HTTPS, with HSTS enabled so a browser refuses to fall back to plain HTTP even if asked to. The app enforces a strict Content-Security-Policy on every page (no inline scripts without a per-request nonce, no framing by other sites, no loading resources from untrusted origins). Session cookies are HttpOnly and SameSite-restricted — never readable by page JavaScript, never sent cross-site. Data is stored on a single encrypted volume on our hosting provider, Fly.io, in one region.

No passwords, ever

Sign-in is GitHub OAuth only. Tallyhook never asks for, sees, or stores a password for your account — there is no password database to leak. We read your GitHub profile and primary email and nothing else.

Payments

Card details are handled entirely by Stripe, a PCI Level 1 payment processor. They never pass through Tallyhook's servers in any form — we store a Stripe customer and subscription ID, never a card number.

Data isolation between workspaces

Every query in the app is scoped to a workspace ID at the database level, not just hidden in the interface — a bug in a page's UI can't leak another workspace's data, because the query itself never has access to it. Within a workspace, every member sees every client by design (stated plainly in the Privacy Policy too) — that's a deliberate product choice for a small-team tool, not an oversight.

Things we specifically built and tested for

CSV/spreadsheet formula injection — a client or workspace name containing a leading =, +, - or @ is neutralized before it ever reaches an exported file, so opening an exported invoice in Excel or Sheets can't execute anything. Rate limiting on the ingest endpoint, so a leaked collector token can't be used to flood the API or fabricate cost data at scale. Every server action that changes billing, team membership, or pricing is checked against the acting user's actual role on every request, not just hidden behind a UI element.

Reporting an issue

Found something? Email support@tallyhook.dev directly — we'll respond and won't take action against a good-faith report.

This page describes Tallyhook's actual practices as of the date above, honestly, including where we fall short of a large company's security program. It isn't a compliance certification or a substitute for your own due diligence.

Tallyhook

What your AI coding agents cost, and what for.

Product
  • What did it cost to build?
  • Features
  • Pricing
  • Documentation
  • Security
  • Live demo
  • Collector (open source)
  • npm package
Use cases
  • For agencies
  • For engineering teams
Guides
  • How to track Claude Code and Codex costs per client
  • How to bill clients for Claude Code and Codex usage
  • The AI usage pass-through clause
  • AI coding model API prices
Company
  • Privacy Policy
  • Terms of Service
  • support@tallyhook.dev