Skip to main content
Book a Demo
Menu

SECURITY BY ARCHITECTURE

Secure access to Tally—without exposing Tally.

Tally and Prism Node stay inside your environment. Node initiates encrypted outbound communication with Prism Cloud, so no inbound firewall rule or publicly exposed Tally port is required.

Tally and Prism Node remain in the customer environment and connect outbound through a controlled encrypted route to Prism Cloud.
  • CUSTOMER ENVIRONMENT
  • TALLY
  • PRISM NODE
  • OUTBOUND ENCRYPTED
  • PRISM CLOUD

Prism security at a glance

OUTBOUND ONLY

Node initiates connections

NO INBOUND PORT

Tally stays behind the firewall

ENCRYPTED IN TRANSIT

HTTPS internet traffic

SERVER-SIDE CONTROL

Access checked centrally

SEPARATED DATA

Customer boundaries enforced

DATA BOUNDARY

See exactly what stays, what moves and what returns.

Prism extends Tally through a controlled working copy of relevant operational data—not by opening Tally to the internet.

  1. STAYS IN YOUR ENVIRONMENT

    Tally company data and Prism Node

  2. MOVES TO PRISM CLOUD

    Relevant operational data

  3. CREATED IN PRISM

    Workflow states, approvals and operational records

  4. RETURNS THROUGH NODE

    Approved transactions, status and references

  1. STAYS IN YOUR ENVIRONMENT

    Tally company data and Prism Node

  2. MOVES TO PRISM CLOUD

    Relevant operational data

  3. CREATED IN PRISM

    Workflow states, approvals and operational records

  4. RETURNS THROUGH NODE

    Approved transactions, status and references

Tally remains the system of record.

ACCESS ENFORCEMENT

Every request passes three checks.

Signing in is only the start. Prism verifies the user, authorises the requested action and applies the correct customer, company and warehouse scope before data is returned.

  1. AUTHENTICATE

    Is the user signed in?

  2. AUTHORISE

    Can this action be performed?

  3. APPLY SCOPE

    Which records apply?

  4. RETURN RESULT

    Allowed data only

POLICY DECISION
ALLOWEDRequest continues
DENIEDDenied by default
  1. AUTHENTICATE

    Is the user signed in?

  2. AUTHORISE

    Can this action be performed?

  3. APPLY SCOPE

    Which records apply?

POLICY DECISION

RETURN RESULT

Allowed data only

ALLOWEDRequest continues
DENIEDDenied by default

OPERATIONAL FOUNDATIONS

Security is integral to every connection and action.

Prism protects credentials and traffic, separates environments and data scope, and governs production change with traceable operational evidence.

PROTECT

  • MANAGED SECRETS

    Credentials kept out of application code.

  • ENCRYPTED TRAFFIC

    Internet communications use HTTPS.

ISOLATE

  • SEPARATED ENVIRONMENTS

    DEV, QA and LIVE remain isolated.

  • SCOPED DATA ACCESS

    Customer, company and warehouse boundaries are enforced.

GOVERN & EVIDENCE

  • CONTROLLED RELEASES

    Production change follows controlled promotion.

  • STRUCTURED LOGGING

    Events and references support investigation.

CONNECTIVITY RESILIENCE

Temporary interruption does not mean lost or duplicated work.

When a connection is interrupted, Prism queues pending exchanges, retries in a controlled sequence and checks for duplicate submissions before confirmation.

  1. QUEUED

    Exchange queued locally

  2. RETRYING

    Retry in controlled sequence

  3. DUPLICATE CHECK

    Check for duplicate submission

  4. SUBMITTED

    Send to Prism successfully

  5. CONFIRMED

    Exchange confirmed

DUPLICATE BLOCKEDNot submitted
  1. QUEUED

    Exchange queued locally

  2. RETRYING

    Retry in controlled sequence

  3. DUPLICATE CHECK

    Check for duplicate submission

  4. SUBMITTED

    Send to Prism successfully

  5. CONFIRMED

    Exchange confirmed

Scoped to temporary connectivity interruption—not backup or disaster recovery.

SHARED RESPONSIBILITY

Security works when the boundary is clear.

Prism protects the cloud service and controlled exchange. You remain in control of the environment, accounts and devices around Tally.

PRISM PROTECTS

  • Cloud application and managed services
  • Server-side access enforcement
  • Customer, company and warehouse data scope
  • Node-to-cloud exchange protocol
  • Managed application secrets
  • Cloud logging and release controls
CONTROLLED EXCHANGE

YOU CONTROL

  • Tally configuration and authorised users
  • Prism Node host, network and physical access
  • User onboarding and removal
  • Passwords and device security
  • Local Tally backup and recovery
  • Endpoint and firewall management

CLOUD LOCATION

Prism application services run in Google Cloud europe-west1.

PRACTICAL QUESTIONS

Straight answers to the questions buyers ask.

Clear architecture deserves clear explanations.

EXTEND TALLY WITH CONFIDENCE

Protect the system you rely on. Extend it with confidence.

Prism creates a controlled route from Tally to the operational workflows your teams need—without exposing Tally to the internet.

Book a demo
A controlled outbound path extends Tally through Prism Node to Prism operational workflows.
  • TALLY DATA
  • PRISM NODE
  • CONTROLLED OUTBOUND PATH
  • PRISM OPERATIONAL WORKFLOWS