Security & Trust
Last updated: July 2026
AITally.me is built for teams and businesses that need to trust the platform their people rely on every day — not just the models behind it. Here's exactly how we protect your data.
Encryption
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to authorized personnel and logged.
Single sign-on (Enterprise)
Business workspaces support SSO/SAML, so access follows your existing identity provider and offboarding a team member from your IdP revokes their AITally.me access immediately.
No training on customer data
We do not use your prompts, files, or outputs to train our own models. When your Content is routed to a model provider (OpenAI, Anthropic, Google, and others) to generate a response, we use business/enterprise access methods under which providers state they do not train on submitted Content. Provider practices can change and are outside our control — see our Privacy Policy for the full detail.
Data residency
Data residency options are available for customers with regional requirements (including GCC and EU buyers). Contact your account team to discuss residency needs before rollout.
Audit logs
Business workspaces include audit logs covering authentication, access, and administrative actions, so admins can see who did what and when.
Data Processing Agreement
A DPA is available on request for customers who need one — contact privacy@aitally.me.
Compliance attestations
We're happy to share our current compliance posture and any available reports under NDA — contact security@aitally.me with your procurement questions.
Reporting a security issue
If you believe you've found a security vulnerability, please report it to security@aitally.me. We investigate all reports promptly.
Questions
For anything not covered here — including questions from your security or procurement team — email security@aitally.me.