Security & Trust

Last updated: July 2026

AITally.me is built for teams and businesses that need to trust the platform their people rely on every day — not just the models behind it. Here's exactly how we protect your data.

Encryption

Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to authorized personnel and logged.

Single sign-on (Enterprise)

Business workspaces support SSO/SAML, so access follows your existing identity provider and offboarding a team member from your IdP revokes their AITally.me access immediately.

No training on customer data

We do not use your prompts, files, or outputs to train our own models. When your Content is routed to a model provider (OpenAI, Anthropic, Google, and others) to generate a response, we use business/enterprise access methods under which providers state they do not train on submitted Content. Provider practices can change and are outside our control — see our Privacy Policy for the full detail.

Data residency

Data residency options are available for customers with regional requirements (including GCC and EU buyers). Contact your account team to discuss residency needs before rollout.

Audit logs

Business workspaces include audit logs covering authentication, access, and administrative actions, so admins can see who did what and when.

Data Processing Agreement

A DPA is available on request for customers who need one — contact privacy@aitally.me.

Compliance attestations

We're happy to share our current compliance posture and any available reports under NDA — contact security@aitally.me with your procurement questions.

Reporting a security issue

If you believe you've found a security vulnerability, please report it to security@aitally.me. We investigate all reports promptly.

Questions

For anything not covered here — including questions from your security or procurement team — email security@aitally.me.