Security above all
Accountants work with the most sensitive data. That's why Wally was built from day one with security and GDPR as its foundation.

How Wally protects your data
EU hosting
All your data is hosted and processed within the European Union. Nothing ever leaves GDPR territory.
GDPR by design
Privacy is not an afterthought checkbox. Wally was built from day one on the principles of data minimisation and purpose limitation.
Encryption from A to Z
Encrypted in transit and at rest. Strong cryptographic standards for every byte we store for you.
Never AI training on your data
Your client data, questions or answers are never used to train our models.
The only exception: anonymous up- and downvotes on answers help us fine-tune Wally.
Sources cited with every answer
With every answer, Wally shows exactly where the information comes from. Every insight stays verifiable — no black box.
Complete data isolation per firm
Every firm works in its own isolated environment. Your files can never mix with those of another firm.
What we do as standard
A look under the hood. Concrete measures we apply every day to keep your data and your clients' data safe.
Infrastructure & access
- Hosting entirely within the EU
- Strong authentication and session management
- Role-based access rights
- Encryption of data at rest and in transit
Data & privacy
- No AI training on client data (only anonymous feedback)
- Complete data isolation per firm
- Audit logs of every action in Wally
- Access and deletion rights on request
Product & development
- Sources cited with every answer
- Continuous code scanning by Aikido
- Real-time monitoring and alerting
- Periodic security testing
People & processes
- Production access strictly limited to those who really need it
- Security and privacy training for the entire Wally team
- Incident response procedure with clear reporting lines
- Data processing agreement (DPA) standard with every client
Continuously monitored by Aikido
Our code, infrastructure and dependencies are scanned 24/7 for vulnerabilities, leaks and misconfigurations via the Aikido security platform. That way we catch problems before they ever reach production.
Sub-processors
Wally uses a limited number of trusted sub-processors to make the service possible. All with EU hosting and watertight data processing agreements.
Google Cloud Platform
Cloud infrastructure
Amazon Web Services
Cloud infrastructure
MongoDB Atlas
Database
Turbopuffer
Database
Redis Cloud
Cache & queues
PostHog
Product analytics
Aikido
Code security monitoring
Dagster
Data orchestration
Policies and contact
Documents to read through and direct lines for when you really need us.
Privacy policy
How Wally processes and protects your personal data.
Read the privacy policyTerms and conditions
The legal terms under which we offer Wally.
View the termsData processing agreement (DPA)
A standard part of every client contract — all our clients have one.
Request a copyTransparency from A to Z
Want to see exactly how this works? During our demo we show you step by step how Wally handles your data. Rather get started right away? Try Wally for free now.