TRUST & SECURITY

Know the source. Know the boundary.

Your entry, automated recognition, a laboratory result, a CannaTally calculation and an official state-program rule are different kinds of information. CannaTally is designed to keep those distinctions visible.

YOU

What you entered

Information you enter should remain attributable to you rather than being presented as a regulator, laboratory, or CannaTally assertion.

SCAN

What automation recognized

Scanned or extracted information should remain reviewable so recognition errors can be corrected before they are relied on as your record.

ESTIMATE

What CannaTally calculated

Allotment views, summaries, forecasts, comparisons, and other calculations must be identified as CannaTally outputs rather than official government records.

OFFICIAL

What came from an authority

State-program and regulatory information should identify its jurisdiction and authoritative source. A rule from one state must never silently become the rule for another.

LAB / COA

What a laboratory reported

Laboratory values should remain connected to the relevant report, product or batch and source instead of being silently rewritten as a CannaTally claim.

PRIVACY

Sensitive records stay out of acquisition analytics

The public website's acquisition layer is intentionally separate from cannabis history, journal, allotment, and other sensitive signed-in records.

SECURITY BY BOUNDARY

Collect less. Expose less. Promise only what is verified.

CannaTally's Website design minimizes acquisition data, keeps integration credentials server-only, validates support submissions, and fails closed when an authoritative application-side support case cannot be created. Security and privacy claims should describe controls that actually exist—not aspirational features presented as guarantees.