Security and compliance
Tabulay runs entirely on the Mac, with no network access. Here is exactly what it does with data, requirement by requirement.
For security, risk and compliance teams evaluating Tabulay. Last updated: 27 September 2026, Tabulay 1.0.0.
In short
Tabulay is a macOS app for viewing and editing CSV and Excel files. It runs entirely on the Mac: App Sandbox, no network access, no accounts, no telemetry. When a file holds payment card data, Tabulay masks card numbers in the grid and the inspector, keeps copies from the grid off clipboard history, warns before a column of card numbers is saved in full, and truncates them to the last four digits in one step. The exceptions are listed below.
What this document is and isn't. PCI DSS and ISO/IEC 27001 apply to organizations, not to software: no desktop app can be "PCI compliant" or "ISO 27001 certified" on its own. What matters is whether a tool lets an organization meet its own obligations. This overview shows, requirement by requirement, what Tabulay does, what it leaves to you, and where it doesn't apply.
Tabulay isn't payment software. It doesn't accept, authorize or transmit payments, so the PCI Secure Software Standard doesn't apply to it. It isn't a third-party service provider under PCI DSS either: it never stores, processes or transmits data on anyone's behalf, and its publisher never has access to your data.
What Tabulay does with your data
| Where data goes | Only into the files you save. Tabulay has no network entitlement: the operating system blocks any connection. |
| Files it can open | Only the ones you pick (App Sandbox, user-selected files). Library folders you add are remembered as sandbox bookmarks. |
| Working copies | Files over 64 MB (64,000,000 bytes) are copied into a query database, and very large queries can spill to temporary files. Both live in Tabulay's sandbox container, in a folder per running copy of the app, and are deleted when the file closes; any left by a crash or force quit are deleted at the next launch. Settings ▸ Security ▸ "Keep working copies in memory only" turns them off entirely, for files opened afterwards. |
| Queries | SQL runs inside Tabulay against the open file only. Once a file is loaded, the query engine can't read or write any other file, load extensions or change its own settings, and each query runs as a single statement. |
| Column profile and insights | Computed by Tabulay on the Mac, in memory, from the rows in view (at most the first 100,000). Never stored or sent. |
| Edits | Kept in memory until you save. Saving writes a new file and swaps it in atomically. No autosave copies, and no versions kept elsewhere (File ▸ Revert to Saved only). |
| Settings | Preferences, recent files and saved queries, in the app's own container. No file contents, though a saved query keeps whatever text you typed into it. |
| Crash reports | Only if the user shares analytics with Apple in macOS settings. They contain no file contents. |
| Feedback | Help ▸ Send Feedback opens the user's own mail app with a message they review and send themselves. It never includes file contents, names or paths. |
Card data protections
Card numbers (PANs) are found by length (13 to 19 digits, spaces or dashes allowed), the Luhn checksum and the issuer prefixes of the major networks, whether a cell holds only the number or the number sits in other text ("paid with 4111 1111 1111 1111"). To flag columns, Tabulay samples up to 5,000 rows spread across the whole file: a column holds card data when card numbers make up at least half of its long numbers (13 to 19 digits). A column of real card numbers passes that easily; a column of random 16-digit IDs doesn't, since only about one in ten passes the checksum. Save warnings then count every row of the flagged columns. Card numbers in a column that isn't flagged are still masked on screen, but the save warning doesn't count them and Mask Card Numbers doesn't cover them.
| Protection | Default | Setting |
|---|---|---|
| Card numbers masked on screen, last four digits shown: the grid, the inspector (column, row and history), the Remove Duplicates and Compare previews, and query error messages | On | Settings ▸ Security |
| Every copy Tabulay makes that contains card numbers (cells, the history's pipeline, query plans) stays on this Mac (no Universal Clipboard) and is marked concealed and transient, so clipboard history apps don't record it | On | Settings ▸ Security |
| Warning before a save (⌘S, Save As, or Save when closing or quitting) or Export View writes full card numbers in flagged columns, and before Export Diff writes any, with "Mask and Save" / "Mask and Export" | On | Settings ▸ Security |
| Warning for columns named like security codes, PINs or track data (CVV, CVC, CID, PIN, track 1/2…) | On | same |
| Data ▸ Mask Card Numbers: keeps the last four digits of every card number in the flagged columns, as one undoable step | Command | Free, not part of Tabulay Pro |
| Working copies in memory only | Off | Settings ▸ Security |
Where full numbers still show. Editing a cell shows its full value. Text you type yourself stays as typed: the SQL editor, filter chips (including those added by "Show Only" from a cell's menu or by clicking a bar in the inspector) and saved queries. The Transform, Normalize and Import previews show values as they are. Text copied from the cell editor or the SQL editor uses the standard text copy, without the clipboard protection. For a read-only file (over the size limit), the save warning can't offer "Mask and Save", since the file can't be edited; Export View can still mask what it writes.
Masking is for display and storage; it isn't access control, because anyone who can open the file can read it.
PCI DSS v4.0.1
| Requirement | How Tabulay supports it | Your part |
|---|---|---|
| 3.2.1 Keep account data storage to a minimum | Mask Card Numbers truncates to the last four digits before a file is kept or shared. | Retention policy; deleting files you no longer need. |
| 3.3.1 No sensitive authentication data after authorization (3.3.1.1 track data, 3.3.1.2 card verification codes, 3.3.1.3 PINs and PIN blocks) | Columns named like these are flagged when the file opens and before every save. | Deleting those columns; not exporting them from source systems. |
| 3.4.1 PAN masked when displayed, at most BIN and last four | On by default: last four only, in the places listed above (see "Where full numbers still show"). | Keeping the setting on (enforceable by MDM, below). |
| 3.4.2 Technical controls against copying PAN over remote access | Copies holding card numbers stay local and are concealed from clipboard managers. Tabulay makes no remote connections of its own. | Remote-access tool configuration (screen sharing, clipboard sync). |
| 3.5.1 PAN unreadable anywhere it's stored | Truncation, one of the methods 3.5.1 accepts, in one step, with a save warning while full numbers remain. | Masking before saving, or keeping the file only where your controls allow. |
| 3.5.1.2 Disk encryption alone isn't enough on non-removable media | Working copies can be kept in memory only, so no extra copy of full PANs reaches the disk. | FileVault, plus masking or the memory-only setting for files with full PANs. |
| 4.2.1 Strong cryptography over open networks | Not applicable: Tabulay sends nothing over any network. | |
| 5.2, 5.3 Anti-malware | Distributed through the Mac App Store: reviewed by Apple, signed, sandboxed, Hardened Runtime. | Endpoint protection. |
| 6.2.4 Software protected against common attacks | Memory-safe Swift parsers with limits against damaged or hostile files; no macro or formula execution; SQL runs locally as a single statement against the open file, with file access, extensions and settings locked. | |
| 6.3.1 Vulnerabilities identified and managed | A published disclosure policy with fix targets ("Reporting a vulnerability", below). | Keeping Tabulay updated. |
| 6.3.2 Inventory of bespoke and third-party components | CycloneDX software bill of materials (make sbom), from the pinned dependency list and bundled notices. | Adding it to your inventory. |
| 6.3.3 Security patches installed | Updates through the Mac App Store. | Automatic updates, or your MDM. |
| 7, 8 Access control, authentication | Tabulay has no accounts of its own: it runs as the macOS user and opens only what that user picks. | macOS accounts, file permissions, MDM. |
| 10 Audit logs | Tabulay keeps no audit trail of who opened which file. The History tab lists a session's edits but isn't persisted. | macOS unified logging, EDR, file-server auditing. |
| 12.5.2 Scope | A Mac that stores or displays full PANs is in scope, whatever app it uses. Masking and truncation help keep copies out of scope. | Scoping, network segmentation. |
| 12.8 Third-party service providers | Tabulay isn't one: its publisher never has access to your data. |
ISO/IEC 27001:2022, Annex A
| Control | How Tabulay supports it |
|---|---|
| A.5.9 Inventory of information and assets | SBOM for the software itself (make sbom). |
| A.5.12 Classification of information | Card data and authentication data columns are detected and flagged when a file opens. |
| A.5.14 Information transfer | No network transfer at all; clipboard copies of card numbers made by Tabulay stay on the Mac. |
| A.5.19 to A.5.22 Supplier relationships, ICT supply chain | One package, duckdb-swift 1.1.3 (MIT), pinned by exact revision, plus the libraries DuckDB vendors, all listed in the SBOM; a disclosure policy. |
| A.5.34 Privacy and protection of PII | No telemetry, accounts or network access; declared "Data Not Collected" on the App Store from launch. |
| A.8.1 User endpoint devices | Sandboxed, and its security settings can be enforced by MDM. |
| A.8.7 Protection against malware | Reviewed by Apple, signed, sandboxed, Hardened Runtime; no plug-ins or scripting. |
| A.8.8 Management of technical vulnerabilities | A disclosure policy with fix targets (below); updates through the App Store. |
| A.8.9 Configuration management | Managed preferences (below). |
| A.8.10 Information deletion | Working copies deleted on close and after crashes; memory-only mode. |
| A.8.11 Data masking | Display masking by default, in the places listed above; truncation to the last four digits. |
| A.8.12 Data leakage prevention | Save and export warnings, concealed clipboard, no network. |
| A.8.24 Use of cryptography | Tabulay adds no encryption of its own and relies on FileVault for data at rest. Its working copies can be avoided entirely. |
| A.8.25 to A.8.29 Secure development, coding and testing | Version-controlled source, automated tests of parsing, editing, masking and the engine, dependency pinning. |
Enforcing settings with MDM
The Security settings can be enforced with a configuration profile (Custom Settings payload) for the preference domain me.expertiseby.tabulay (the app's bundle ID). Enforced settings are shown as managed and can't be changed in the app.
| Key | Type | Recommended for PCI DSS |
|---|---|---|
security.maskCards | Boolean | true |
security.protectClipboard | Boolean | true |
security.warnCardsOnSave | Boolean | true |
security.memoryOnly | Boolean | true on Macs that handle full card numbers |
Reporting a vulnerability
Email security@tabulay.app with the steps to reproduce, the Tabulay version (Tabulay ▸ About Tabulay) and your macOS version, in English or French. The same contact is in security.txt.
- You get an acknowledgement within 3 business days, and an assessment within 10.
- Fix targets from the assessment: critical within 14 days, high within 30, medium and low in the next scheduled release.
- You're credited in the release notes, unless you'd rather not be.
- Good-faith research within this policy won't be pursued legally.
Only the latest release on the Mac App Store gets security fixes. Never send real card numbers or personal data in a report: use test data, such as the networks' test card numbers.
Other questions: hello@tabulay.app.