Why
PR #102 removed two market documents from the public repo. Automated review then surfaced eleven findings, all one class: the retained plan asserts facts a public contributor cannot verify, while docs/tally/README.md designates it the public execution authority.
Ten were fixed in that PR. Two of them were not citation gaps but wrong claims:
- §2.2.4 regulatory tailwind — read "since Jan 2026, excess ITC vs GSTR-2B auto-flags on the portal". GSTR-3B hard-locking is phased: Table 3 (outward) since July 2025; ITC (Table 4) targeted ~July 2026, not in force; the Jan-2026 advisory concerned interest. Corrected.
- Biz Analyst data handling — asserted the Play Store data-safety page "admits unencrypted data shared with third parties". Contradicted by the vendor's own privacy policy, which describes encryption measures while confirming only the sharing half. Retracted.
The remaining problem
PR #102's source block claimed to be exhaustive over §2.1–2.4. That promise was stronger than the PR could deliver, and review kept finding omissions because the document has never had a full provenance audit. The promise has been narrowed to what is actually covered; this issue tracks finishing the job.
Known outstanding claims
| Claim |
Location |
State |
| Vyapar "10k+ CA firms, 30k+ accountants" |
§2.1 |
vendor page not retrieved |
| CredFlow sync-reliability complaints |
§2.1, §2.2.2 |
linked to the syncing-issues folder; verify it still carries them |
| Tally GSTR-2B recon + 7.x AI features |
§2.1, defers GSTR work |
uncited |
| 7th/11th/20th filing rhythm |
§2.3 |
which returns and taxpayer categories? currently shorthand |
| Finsights 24h deletion latency |
§2.1, §0, §4.2 |
finsights.biz 403 on re-fetch; a wedge rests on it |
| "6–10 hrs/GSTIN/month VLOOKUP baseline" |
§2.1 |
uncited; implicit denominator for time-saving arguments |
| "50–200 companies per firm", hour pools |
§2.3 |
internal estimates |
| GSTN/MCA primary sources |
§2.2.4 |
only secondary summaries retrieved |
Scope
Go claim by claim through §§0–4. For each: cite a primary source, or mark it an internal estimate/hypothesis. Prefer marking over citing where the source cannot be retrieved — an honest gap beats a link that implies strength it lacks.
Any claim about a named competitor's security or data handling must be sourced or removed, not graded. That is what went wrong with the Biz Analyst row and it is the one rule this audit exists to enforce.
Why
PR #102 removed two market documents from the public repo. Automated review then surfaced eleven findings, all one class: the retained plan asserts facts a public contributor cannot verify, while
docs/tally/README.mddesignates it the public execution authority.Ten were fixed in that PR. Two of them were not citation gaps but wrong claims:
The remaining problem
PR #102's source block claimed to be exhaustive over §2.1–2.4. That promise was stronger than the PR could deliver, and review kept finding omissions because the document has never had a full provenance audit. The promise has been narrowed to what is actually covered; this issue tracks finishing the job.
Known outstanding claims
finsights.biz403 on re-fetch; a wedge rests on itScope
Go claim by claim through §§0–4. For each: cite a primary source, or mark it an internal estimate/hypothesis. Prefer marking over citing where the source cannot be retrieved — an honest gap beats a link that implies strength it lacks.
Any claim about a named competitor's security or data handling must be sourced or removed, not graded. That is what went wrong with the Biz Analyst row and it is the one rule this audit exists to enforce.