Security & Privacy
We treat your financial data the way we want our own to be treated. Solid engineering and clear rules. Here is exactly how we secure your app.
Core protections
Encrypted in transit
Everything moves through secure HTTPS connections. No exceptions. We use modern TLS protocols to keep your data safe from eavesdropping.
Two-factor authentication (2FA)
Secure your account with an authenticator app. Even if your password leaks somewhere else, your Talero workspace remains locked.
Strict session management
Your login tokens are locked down. We use secure, HttpOnly cookies where applicable to prevent session hijacking.
Hashed passwords
We don't know your password. We only store a secure cryptographic hash. Even if we wanted to read it, we couldn't.
Under the hood
Tenant isolation
Each workspace is strictly separated at the database level. Your data never accidentally leaks into someone else's view.
Zero-trust API
Before any action runs, our backend verifies your identity and permissions. No guessing, no bypassing rules. If it doesn't match, we drop the request.
Role-based access
Granular permissions under the hood. You, your team, or your accountant only reach the endpoints your role explicitly allows.
Automated testing
Every code update goes through hundreds of automated CI/CD tests before hitting production. Security isn't just an afterthought; it's built into the pipeline.
Continuous backups
Our database provider keeps a rolling history of your data, so if something ever breaks on our end, your records can be restored rather than lost for good.
Your data is yours
You are the customer, not the product
We charge for a great tool. We don't sell your data, we don't profile your spending habits, and we don't run ads.
No vendor lock-in
Don't want to use Talero anymore? Export your data in a standard format and take it with you. You are never trapped.
Privacy by default
We don't use marketing or tracking cookies. We only measure basic, fully anonymized app performance analytics. Your data remains strictly yours.
Your setup, your rules
Turn modules off, hide features you don't need. You shape the app, we just provide the tools.
Hosted in the EU
We don't use black-box servers. We partner with industry-leading, privacy-respecting providers based in Europe.
Vercel
Fast, globally distributed frontend hosting. Ensures the app loads instantly wherever you are.
Hetzner
Solid, no-nonsense European cloud infrastructure. This is where our backend does the heavy lifting.
Neon
Serverless Postgres, hosted in Germany — the same country as our backend. This is where your encrypted transactions and records actually live, with continuous backups running in the background.
Cloudflare
Our first line of defense. Provides DNS routing and protects our servers against DDoS attacks and malicious traffic.
Collaboration
Separate workspaces
Keep your freelance business and personal budget in completely different, isolated workspaces.
Strict user roles
Invite an editor or a read-only viewer. Sensitive actions always require explicit Owner permissions.
Audit logs
Important edits leave a trace. See exactly who changed what and when, preventing unwanted surprises in shared workspaces.
Privacy and GDPR
We comply with GDPR, but we go further than just a legal checkbox. You can view what we store, change your preferences, or completely delete your account and all associated data with a single click. No dark patterns. Just simple, honest privacy.
Read the full details in our Privacy Policy.
Spotted a security issue? Please report it via our Contact page.
Curious what runs under the hood?
Check out our Tech Stack →