Constrained Semantic Actions
The model cannot send arbitrary scripts to Desktop; every operation must match a defined schema.
Tablyra's security model is not a generic privacy promise. It explicitly separates local processing, planner context, account metadata, and user-submitted feedback.
The model cannot send arbitrary scripts to Desktop; every operation must match a defined schema.
Column references must match the current source schema and ambiguous headers require clarification.
Client code transforms the file; model-generated code is not run in a remote sandbox.
Source, Result, Diff, and Issues are visible before output.
Source replacement creates a backup and re-reads the written output for verification.
Logs are size-limited and filter common paths, credentials, tokens, and sensitive patterns.
Tablyra currently provides documented data boundaries, constrained execution, device management, audit records, and error diagnostics. Enterprise certifications, formal data-processing agreements, and advanced deployment controls remain part of the future team roadmap.
No. Full files and full rows remain in Desktop. Planning uses the current instruction, schema, statistics, and a small set of samples approved by the user.
The service stores account, device, usage, product events, error reports, and feedback explicitly submitted by users. Tasks and conversations remain local.
Diagnostic logging filters paths, tokens, credentials, and common sensitive values and limits package size. A package is uploaded only when the user explicitly includes it with feedback.
A new output is the default. Source replacement runs only after an explicit choice, backup creation, write, and output verification.
The current beta does not claim these certifications. Team evaluations should use the documented data boundaries, deployment model, and available security materials rather than assuming certification.
Download the desktop app, open an Excel or CSV file locally, and build a reviewable result through conversation.