security for IT and compliance teams

Security and compliance

Tabulay runs entirely on the Mac, with no network access. Here is exactly what it does with data, requirement by requirement.

For security, risk and compliance teams evaluating Tabulay. Last updated: 27 September 2026, Tabulay 1.0.0.

In short

Tabulay is a macOS app for viewing and editing CSV and Excel files. It runs entirely on the Mac: App Sandbox, no network access, no accounts, no telemetry. When a file holds payment card data, Tabulay masks card numbers in the grid and the inspector, keeps copies from the grid off clipboard history, warns before a column of card numbers is saved in full, and truncates them to the last four digits in one step. The exceptions are listed below.

What this document is and isn't. PCI DSS and ISO/IEC 27001 apply to organizations, not to software: no desktop app can be "PCI compliant" or "ISO 27001 certified" on its own. What matters is whether a tool lets an organization meet its own obligations. This overview shows, requirement by requirement, what Tabulay does, what it leaves to you, and where it doesn't apply.

Tabulay isn't payment software. It doesn't accept, authorize or transmit payments, so the PCI Secure Software Standard doesn't apply to it. It isn't a third-party service provider under PCI DSS either: it never stores, processes or transmits data on anyone's behalf, and its publisher never has access to your data.

What Tabulay does with your data

Where data goesOnly into the files you save. Tabulay has no network entitlement: the operating system blocks any connection.
Files it can openOnly the ones you pick (App Sandbox, user-selected files). Library folders you add are remembered as sandbox bookmarks.
Working copiesFiles over 64 MB (64,000,000 bytes) are copied into a query database, and very large queries can spill to temporary files. Both live in Tabulay's sandbox container, in a folder per running copy of the app, and are deleted when the file closes; any left by a crash or force quit are deleted at the next launch. Settings ▸ Security ▸ "Keep working copies in memory only" turns them off entirely, for files opened afterwards.
QueriesSQL runs inside Tabulay against the open file only. Once a file is loaded, the query engine can't read or write any other file, load extensions or change its own settings, and each query runs as a single statement.
Column profile and insightsComputed by Tabulay on the Mac, in memory, from the rows in view (at most the first 100,000). Never stored or sent.
EditsKept in memory until you save. Saving writes a new file and swaps it in atomically. No autosave copies, and no versions kept elsewhere (File ▸ Revert to Saved only).
SettingsPreferences, recent files and saved queries, in the app's own container. No file contents, though a saved query keeps whatever text you typed into it.
Crash reportsOnly if the user shares analytics with Apple in macOS settings. They contain no file contents.
FeedbackHelp ▸ Send Feedback opens the user's own mail app with a message they review and send themselves. It never includes file contents, names or paths.

Card data protections

Card numbers (PANs) are found by length (13 to 19 digits, spaces or dashes allowed), the Luhn checksum and the issuer prefixes of the major networks, whether a cell holds only the number or the number sits in other text ("paid with 4111 1111 1111 1111"). To flag columns, Tabulay samples up to 5,000 rows spread across the whole file: a column holds card data when card numbers make up at least half of its long numbers (13 to 19 digits). A column of real card numbers passes that easily; a column of random 16-digit IDs doesn't, since only about one in ten passes the checksum. Save warnings then count every row of the flagged columns. Card numbers in a column that isn't flagged are still masked on screen, but the save warning doesn't count them and Mask Card Numbers doesn't cover them.

ProtectionDefaultSetting
Card numbers masked on screen, last four digits shown: the grid, the inspector (column, row and history), the Remove Duplicates and Compare previews, and query error messagesOnSettings ▸ Security
Every copy Tabulay makes that contains card numbers (cells, the history's pipeline, query plans) stays on this Mac (no Universal Clipboard) and is marked concealed and transient, so clipboard history apps don't record itOnSettings ▸ Security
Warning before a save (⌘S, Save As, or Save when closing or quitting) or Export View writes full card numbers in flagged columns, and before Export Diff writes any, with "Mask and Save" / "Mask and Export"OnSettings ▸ Security
Warning for columns named like security codes, PINs or track data (CVV, CVC, CID, PIN, track 1/2…)Onsame
Data ▸ Mask Card Numbers: keeps the last four digits of every card number in the flagged columns, as one undoable stepCommandFree, not part of Tabulay Pro
Working copies in memory onlyOffSettings ▸ Security

Where full numbers still show. Editing a cell shows its full value. Text you type yourself stays as typed: the SQL editor, filter chips (including those added by "Show Only" from a cell's menu or by clicking a bar in the inspector) and saved queries. The Transform, Normalize and Import previews show values as they are. Text copied from the cell editor or the SQL editor uses the standard text copy, without the clipboard protection. For a read-only file (over the size limit), the save warning can't offer "Mask and Save", since the file can't be edited; Export View can still mask what it writes.

Masking is for display and storage; it isn't access control, because anyone who can open the file can read it.

PCI DSS v4.0.1

RequirementHow Tabulay supports itYour part
3.2.1 Keep account data storage to a minimumMask Card Numbers truncates to the last four digits before a file is kept or shared.Retention policy; deleting files you no longer need.
3.3.1 No sensitive authentication data after authorization (3.3.1.1 track data, 3.3.1.2 card verification codes, 3.3.1.3 PINs and PIN blocks)Columns named like these are flagged when the file opens and before every save.Deleting those columns; not exporting them from source systems.
3.4.1 PAN masked when displayed, at most BIN and last fourOn by default: last four only, in the places listed above (see "Where full numbers still show").Keeping the setting on (enforceable by MDM, below).
3.4.2 Technical controls against copying PAN over remote accessCopies holding card numbers stay local and are concealed from clipboard managers. Tabulay makes no remote connections of its own.Remote-access tool configuration (screen sharing, clipboard sync).
3.5.1 PAN unreadable anywhere it's storedTruncation, one of the methods 3.5.1 accepts, in one step, with a save warning while full numbers remain.Masking before saving, or keeping the file only where your controls allow.
3.5.1.2 Disk encryption alone isn't enough on non-removable mediaWorking copies can be kept in memory only, so no extra copy of full PANs reaches the disk.FileVault, plus masking or the memory-only setting for files with full PANs.
4.2.1 Strong cryptography over open networksNot applicable: Tabulay sends nothing over any network.
5.2, 5.3 Anti-malwareDistributed through the Mac App Store: reviewed by Apple, signed, sandboxed, Hardened Runtime.Endpoint protection.
6.2.4 Software protected against common attacksMemory-safe Swift parsers with limits against damaged or hostile files; no macro or formula execution; SQL runs locally as a single statement against the open file, with file access, extensions and settings locked.
6.3.1 Vulnerabilities identified and managedA published disclosure policy with fix targets ("Reporting a vulnerability", below).Keeping Tabulay updated.
6.3.2 Inventory of bespoke and third-party componentsCycloneDX software bill of materials (make sbom), from the pinned dependency list and bundled notices.Adding it to your inventory.
6.3.3 Security patches installedUpdates through the Mac App Store.Automatic updates, or your MDM.
7, 8 Access control, authenticationTabulay has no accounts of its own: it runs as the macOS user and opens only what that user picks.macOS accounts, file permissions, MDM.
10 Audit logsTabulay keeps no audit trail of who opened which file. The History tab lists a session's edits but isn't persisted.macOS unified logging, EDR, file-server auditing.
12.5.2 ScopeA Mac that stores or displays full PANs is in scope, whatever app it uses. Masking and truncation help keep copies out of scope.Scoping, network segmentation.
12.8 Third-party service providersTabulay isn't one: its publisher never has access to your data.

ISO/IEC 27001:2022, Annex A

ControlHow Tabulay supports it
A.5.9 Inventory of information and assetsSBOM for the software itself (make sbom).
A.5.12 Classification of informationCard data and authentication data columns are detected and flagged when a file opens.
A.5.14 Information transferNo network transfer at all; clipboard copies of card numbers made by Tabulay stay on the Mac.
A.5.19 to A.5.22 Supplier relationships, ICT supply chainOne package, duckdb-swift 1.1.3 (MIT), pinned by exact revision, plus the libraries DuckDB vendors, all listed in the SBOM; a disclosure policy.
A.5.34 Privacy and protection of PIINo telemetry, accounts or network access; declared "Data Not Collected" on the App Store from launch.
A.8.1 User endpoint devicesSandboxed, and its security settings can be enforced by MDM.
A.8.7 Protection against malwareReviewed by Apple, signed, sandboxed, Hardened Runtime; no plug-ins or scripting.
A.8.8 Management of technical vulnerabilitiesA disclosure policy with fix targets (below); updates through the App Store.
A.8.9 Configuration managementManaged preferences (below).
A.8.10 Information deletionWorking copies deleted on close and after crashes; memory-only mode.
A.8.11 Data maskingDisplay masking by default, in the places listed above; truncation to the last four digits.
A.8.12 Data leakage preventionSave and export warnings, concealed clipboard, no network.
A.8.24 Use of cryptographyTabulay adds no encryption of its own and relies on FileVault for data at rest. Its working copies can be avoided entirely.
A.8.25 to A.8.29 Secure development, coding and testingVersion-controlled source, automated tests of parsing, editing, masking and the engine, dependency pinning.

Enforcing settings with MDM

The Security settings can be enforced with a configuration profile (Custom Settings payload) for the preference domain me.expertiseby.tabulay (the app's bundle ID). Enforced settings are shown as managed and can't be changed in the app.

KeyTypeRecommended for PCI DSS
security.maskCardsBooleantrue
security.protectClipboardBooleantrue
security.warnCardsOnSaveBooleantrue
security.memoryOnlyBooleantrue on Macs that handle full card numbers

Reporting a vulnerability

Email security@tabulay.app with the steps to reproduce, the Tabulay version (Tabulay ▸ About Tabulay) and your macOS version, in English or French. The same contact is in security.txt.

  • You get an acknowledgement within 3 business days, and an assessment within 10.
  • Fix targets from the assessment: critical within 14 days, high within 30, medium and low in the next scheduled release.
  • You're credited in the release notes, unless you'd rather not be.
  • Good-faith research within this policy won't be pursued legally.

Only the latest release on the Mac App Store gets security fixes. Never send real card numbers or personal data in a report: use test data, such as the networks' test card numbers.

Other questions: hello@tabulay.app.