Skip to content
TaktSignal

Trust center · Community Alpha

Know exactly what you are installing.

TaktSignal is early software from a small team. We think the right way to earn trust is to be precise: what it does, where your data goes, what has not been tested yet — without needing access to our source code.

The trust model

Your ERPNext.Your machine.Your database.Your factory data.

TaktSignal reads operational information from ERPNext to help surface risk. It does not need to watch you.

What we promise — and test

  • Read-only ERPNext connection

    TaktSignal uses a dedicated ERPNext account that can only read. TaktSignal only sends read requests — it never creates, changes, submits or deletes anything in ERPNext — and setup stops if ERPNext reports write permissions for the account.

  • Your data is stored locally — on purpose

    TaktSignal keeps an operational copy of the ERPNext data it reads in its own PostgreSQL database on your computer. It needs that copy to work. It is yours, and it stays there.

  • No central collection of factory data

    There is no TaktSignal cloud receiving your data. Factory data is never uploaded to us, never sold, never shared with advertisers and never used to train AI models.

  • No telemetry, no product analytics

    The installed product does not track how you use it. No usage analytics, no crash-reporting service, no installation ID, no device fingerprinting.

  • LLM data sharing is off by default

    Alerts come from documented rules, not AI. The desktop Community Alpha has no AI data sharing at all; server installations can switch on an optional AI wording of the daily brief, which is off by default.

  • Diagnostics only when you ask

    A support file is created only when you click Export diagnostics, and you decide whether to send it. It contains no passwords, API keys, ERPNext address or company, customer, supplier or user names.

Each promise is backed by the code and an automated privacy test. The full reasoning is in the privacy policy and on the security page.

Questions people ask before installing

Is this finished software?

No. TaktSignal is in Community Alpha — early public testing. It works end to end and is tested, but it is not production-proven. Alerts can be wrong or missing. Use it alongside ERPNext and your own judgement, not instead of them.

Why is it called Community Alpha?

TaktSignal has been through substantial automated, synthetic and internal validation, but it has not yet been validated across enough real factories, ERPNext configurations and desktop environments. Community Alpha exists to gather that evidence. What Community Alpha means.

Why is it free?

Because we need real ERPNext users to tell us where TaktSignal is right, wrong or confusing before it can be called finished. Your feedback is the exchange — not your data. TaktSignal does not collect factory data, show ads or sell anything about you.

Why is macOS warning me?

The Community Alpha for Mac is an unsigned test build: it is not signed with an Apple Developer ID or notarized by Apple yet. macOS shows “Apple could not verify TaktSignal is free of malware” for every app like that. It does not mean Apple found malware — and it does not prove the app is safe either. You can verify the download, approve this one app safely (step by step), or wait for a signed release. Never turn off Gatekeeper.

Does TaktSignal modify ERPNext?

No. It uses a dedicated ERPNext account with Read permission only, sends read requests only, and setup stops if ERPNext reports that the account can write. It installs nothing in ERPNext — no apps, custom fields or scripts. How to create the read-only account.

Where is my factory data stored?

On your computer. TaktSignal reads data from ERPNext and keeps an operational copy in its own PostgreSQL database in your user's data folder — it needs that copy to work. Backups and logs stay in the same place. Nothing is stored by us. What exactly is stored.

Does TaktSignal upload my factory data?

No. There is no TaktSignal cloud that receives it. The installed product connects only to your ERPNext and — when you click Check for updates or Install update — to the TaktSignal release server, which receives no factory data.

Does TaktSignal track me?

No. The installed product has no telemetry, no usage analytics, no crash-reporting service, no installation ID and no device fingerprinting. An automated check in our tests fails if any such component is added.

Does this website track me?

No analytics, no advertising or tracking scripts, no cookies, no fingerprinting, and your browser loads nothing from third parties here. Like any website, the web host receives your IP address and browser details with each request and may keep ordinary access logs; we don't use them to profile anyone. Details.

Does AI receive my factory data?

Not by default — and in the desktop Community Alpha, not at all: it has no AI data sharing. Alerts come from documented rules on your computer. (The server edition has an optional AI wording of the daily brief that is off by default and states what it would send before it is used.) We never use factory data to train AI models.

What does the installer install?

TaktSignal, a Node.js runtime and a PostgreSQL database server, inside the TaktSignal application folder, plus a start-at-login entry you can turn off. No administrator rights on macOS or Windows, nothing system-wide, no browser extension. The database runs only on your computer. Details.

What happens during updates?

Nothing, until you ask. TaktSignal never checks or updates on its own. When you click Check for updates, it downloads the signed list of releases (sending no identifiers or factory data); when you click Install update, it verifies the file, backs up your data, switches versions and rolls back automatically if the new version does not start. Updates.

What happens when I uninstall?

By default your data is kept, so a reinstall continues where you left off. Choosing Remove all TaktSignal data (and typing DELETE) deletes the database, backups, settings, logs and saved credentials. Neither option touches ERPNext. Uninstall.

How do I verify the download?

Every download is listed with its SHA-256 checksum, taken from signed release metadata. Calculate the checksum of your file and compare — one command per operating system.

How do I report a suspicious issue?

A suspected security problem: privately, as described on the security page — not in public. Anything else: the support page. Never share API keys, passwords, backups or customer data.

What has been tested

  • macOS — Apple Silicon · Tested Community Alpha

    Installed and taken through setup, restart, reboot, backup/restore and keep-data reinstall on a real Apple Silicon Mac (macOS 26). macOS 12–25 have not been run yet.

  • Linux — x64 (.deb) · Tested Community Alpha

    Automated clean-machine lifecycle on Ubuntu 24.04 (install, setup, restart, crash, repair, backup/restore, update, rollback, uninstall). Ubuntu 22.04 and Debian 12 are declared but not install-tested yet.

  • Windows — x64 · Experimental Community Alpha

    The installer has been built and inspected, but it has not completed the same install validation on a real Windows PC as the tested platforms.

  • macOS — Intel · Pending — not validated

    Not built or tested for this release.

ERPNext versions exercised with synthetic factory data: 15.121.4 and 16.36.0. Other versions may work but are not validated.

Trust without source access

The TaktSignal source repository is not public during Community Alpha, and we don't call TaktSignal open source. You should not have to take our word for anything, so what we offer instead is checkable: a read-only ERPNext account you create and control, a data folder on your own computer you can inspect or delete, no outbound connections except your ERPNext and update checks you trigger (watch them with any firewall), SHA-256 checksums from signed release metadata, redacted diagnostics you can read before sharing, published limitations and a private vulnerability-reporting route.

Questions: work.manhcang@gmail.com