Security and privacy

The full spreadsheet stays on your computer. Cloud services receive only the minimum context needed.

Tablyra's security model is not a generic privacy promise. It explicitly separates local processing, planner context, account metadata, and user-submitted feedback.

Always local

Files and results

  • Full XLSX, XLSM, and CSV files
  • File paths, full rows, and full cell content
  • Local previews, final outputs, and backups
  • Tasks, conversations, merge recipes, and intermediate data
Sent when needed

Planner context

  • Current instruction and validated plan
  • Source and column schema information
  • Profiles such as empty counts and detected types
  • A small set of sample values approved by the user
Service metadata

Account and run records

  • Account, session, and signed-in devices
  • Usage deductions and plan status
  • Request IDs, error codes, and privacy-safe product events
  • Usage, errors, and feedback explicitly submitted by users
Security controls

Reduce risk during planning, execution, writing, and diagnostics.

01

Constrained Semantic Actions

The model cannot send arbitrary scripts to Desktop; every operation must match a defined schema.

02

Schema-aware validation

Column references must match the current source schema and ambiguous headers require clarification.

03

Deterministic local execution

Client code transforms the file; model-generated code is not run in a remote sandbox.

04

Complete preview before write

Source, Result, Diff, and Issues are visible before output.

05

Backup and verification

Source replacement creates a backup and re-reads the written output for verification.

06

Privacy-filtered diagnostics

Logs are size-limited and filter common paths, credentials, tokens, and sensitive patterns.

Transparent boundaries

The beta does not overstate certifications it has not completed.

Tablyra currently provides documented data boundaries, constrained execution, device management, audit records, and error diagnostics. Enterprise certifications, formal data-processing agreements, and advanced deployment controls remain part of the future team roadmap.

FAQ

Frequently asked questions

Is the full workbook sent to an AI service?

No. Full files and full rows remain in Desktop. Planning uses the current instruction, schema, statistics, and a small set of samples approved by the user.

What does the server store?

The service stores account, device, usage, product events, error reports, and feedback explicitly submitted by users. Tasks and conversations remain local.

Can diagnostic packages contain sensitive data?

Diagnostic logging filters paths, tokens, credentials, and common sensitive values and limits package size. A package is uploaded only when the user explicitly includes it with feedback.

Is replacing the source file safe?

A new output is the default. Source replacement runs only after an explicit choice, backup creation, write, and output verification.

Does Tablyra have SOC 2 or ISO 27001 certification?

The current beta does not claim these certifications. Team evaluations should use the documented data boundaries, deployment model, and available security materials rather than assuming certification.

Get started

See every spreadsheet change before you save it.

Download the desktop app, open an Excel or CSV file locally, and build a reviewable result through conversation.