Tellby Detect The Bet Docs
Reference

Security

The design goal is a minimal blast radius. We never receive your data, the feed is verified on your side and fails closed, and the software has no third-party dependencies. There is almost nothing to breach, because we never touch your systems or your customers.

No customer data, by design

In normal operation the feed flows one way. We do not connect to your systems, we receive no transactions, and we hold no personal or cardholder data. We sit outside your cardholder-data environment. The free assessment runs inside your environment by default, so nothing reaches us there either. The only path where any customer-adjacent data can enter is the optional extract, and there the intake refuses and deletes any file containing personal data before it parses anything (in the local kit, a refused file is simply left untouched on your machine).

Integrity and authenticity

  • Signed releases. Every release is signed and verified on your side against a pinned public key. See Verifying a release.
  • Fails closed. An unverified release never loads and never reaches your authorization path.
  • Tamper-evident history. The classification record is hash-chained and sealed into every release, so the signature vouches for the whole audit trail.

Supply chain

The reference client and our build pipeline use only the language standard library plus a standard tool for signature verification. Zero third-party runtime dependencies. You inherit no dependency supply-chain risk from us: there is no package tree to compromise. We can provide a bill of materials that proves it.

What you can verify yourself

The controls are not claims to take on faith. You can verify the signature on any release, and under NDA we provide the material to confirm the rest: the release re-derives from inspectable source, the software carries no third-party dependencies, and the release pipeline enforces its own integrity checks before anything is signed.

The diligence pack

Under NDA we provide a full security package for your risk team: a threat model, a completed vendor security questionnaire, a data-handling and privacy statement, an incident-response plan, a business-continuity plan, and the bill of materials.

Certifications, stated honestly. We do not yet hold a SOC 2 report; a scoped path to one is on our roadmap and we will not claim it before it exists. Because the engagement receives no customer data and can be evaluated in log-only shadow mode, it fits the lowest-risk tier of a third-party risk review.