Per-File MD5, SHA-1 and SHA-256
Each source file gets three hash values, so a second examiner can repeat the check.
Univik Tally Data Forensic Analyzer for Windows
Univik Tally Data Forensic Analyzer is a read-only Tally data forensic analyzer for Windows that auditors, forensic accountants and investigators use to examine company data with no Tally installed. It hashes every source file with MD5, SHA-1 and SHA-256 and shows the TallyPrime Edit Log with deleted and altered vouchers. A date-stamped report covers .500, .900 and .1800 data and .001 backups.
Read-OnlyMD5, SHA-1, SHA-256Edit Log HistoryDate-Stamped Report
*Browsing the data costs nothing, and the trial version exports up to 10 items in each section. The Forensics licence covers 50 PCs and has a 30-day money-back guarantee.
At a Glance
3
Hash Algorithms
MD5, SHA-1 and SHA-256, worked out for every source file.
0
Writes to Evidence
Company folders and backups are opened for reading only.
5
Edit Log Activities
Created, Altered, Renumbered, Resaved and Deleted, as Tally logs them.
6.10
Current Version
Windows 10 and 11 with .NET 4.8. Reports in PDF, CSV or HTML.
$299
Forensics Licence
One licence for 50 PCs. Trial exports stop at 10 items a section.
Key Features
Each source file gets three hash values, so a second examiner can repeat the check.
Every logged version of a voucher or master, with the activity, the username and the date and time Tally recorded.
Entries logged as Deleted or Altered stay visible, so removed and edited vouchers can be listed for the working papers.
Save the hash report as PDF for the file, CSV for analysis or HTML for a browser. Each one carries the date and time.
Folders and .001 backups open without a restore, a migration or a repair, so the files stay as they were seized.
Narrow the review by date range and section, then export the extract to Excel, CSV, PDF or another of the eight formats.
The Short Version
Because accounting software is built to keep the books, not to preserve them as evidence.
Trap 1: Opening Data in Tally Can Change It
Tally's data migration FAQ explains that files ending in 1800 mean the data was accessed in a higher release. A backup also opens only after a Restore writes a new company.
Trap 2: The Certificate Asks for Hash Values
Under the Bharatiya Sakshya Adhiniyam, 2023, the Schedule certificate for an electronic record has a line for its hash value and one for the algorithm. Tally's screens show the books, not a hash of the files behind them.
The Way Out: Hash First, Then Read a Copy
Univik Tally Data Forensic Analyzer reads the company files directly and never writes to them. Our advice: hash the evidence on receipt, examine a working copy, hash again at the end and keep both reports. Quote SHA-256 as the main value and keep MD5 and SHA-1 for forms that still ask for them.
The Audit Trail
Every log entry carries a version number, the activity, the username and the date and time, as Tally's Edit Log help describes.
Created
A New Entry
The first version of a voucher or master, with who made it and when.
Altered
A Changed Entry
A later version. Compare two versions to see which fields moved.
Renumbered
Altered by Renumbering
Logged when voucher renumbering changed an entry, plus Resaved (No Changes) for a save with no edit.
Deleted
A Removed Entry
The entry is gone from the books, but its history stays in the log.
Edit Log arrived in TallyPrime Release 2.1, released on 21 March 2022. Regular TallyPrime lets users switch it off. The TallyPrime Edit Log product keeps it on, and Tally's FAQ says its log data cannot be deleted.
Since the financial year starting 1 April 2023, Rule 3(1) of the Companies (Accounts) Rules, 2014 requires companies to use accounting software with an audit trail that cannot be disabled. A company on regular TallyPrime with Edit Log off, or on a release before 2.1, has no log to examine.
Three Steps
Hash the Tally data, review it read-only and keep a report that a second examiner can check.
Hash the Evidence
Load the company folder or backup. The analyzer records MD5, SHA-1 and SHA-256 for every source file before you start.
Examine Read-Only
Review vouchers, masters and the Edit Log with date range and section filters. Nothing is written to the source.
Save the Report
Save the hash report as PDF, CSV or HTML with its date and time stamp, plus the data in the format the case needs.
Windows 10 and 11 · evidence opened read-only · no Tally needed on the lab PC · built and supported by Univik
Who It Is For
Statutory Auditors
Rule 11(g) asks auditors to report on the audit trail. Keep the year's Edit Log extract with the working papers.
Forensic Accountants
ICAI's Forensic Accounting and Investigation Standards apply from 1 July 2023. FAIS 420 covers digital evidence.
Investigators
Record hash values on receipt for the Section 63 certificate, before anyone opens the books.
Where to Look
The PCAOB fraud standard lists journal entries worth testing: entries to unusual or seldom-used accounts, entries by people who rarely post, end-of-period entries with little description and round numbers.
In Tally data, also check Edit Log Deleted and Altered activities. Vouchers created long after their date in a closed period can point to back-dating.
Compare Your Options
Tally is the right tool for running the books. Seized or received data needs to be read without being touched.
| What the case needs | Open It in TallyPrime | TallyPrime Auditors Edition | Univik Tally Data Forensic AnalyzerTRIAL |
|---|---|---|---|
| Changes the evidence | Can: a newer release turns .900 files into .1800 | Read-only client access via Tally.NET | No, read-only |
| Hash values per file | Not shown on Tally screens | No hash feature listed | MD5, SHA-1 and SHA-256 |
| Edit Log history | On screen; Tally's FAQ says Release 2.1 cannot print it | Inside Tally screens | Shown with the data, filtered by date and section |
| Opens a .001 backup | After a Restore that writes a new company | After a Restore | Directly, no restore |
| Needs a licensed Tally | Yes | Yes, with active TSS and Tally.NET | No |
| Report for the case file | Printed Tally reports | Audit working papers and Form 3CD | Date-stamped hash report as PDF, CSV or HTML |
| Best for | Running the books day to day | Statutory audit work inside Tally | Examining seized or received data |
TallyPrime Auditors Edition is the better fit for working papers and Form 3CD on a live client company. For evidence, hash first and keep the source untouched.
What You Need
Operating System
Any Windows 10 or 11 machine where .NET Framework 4.8 or newer is installed.
No Tally on the Lab PC
The forensic tool reads the company files itself, so the lab PC stays free of TallyPrime and its licence.
Working Copy
Examine a copy of the seized folder. Keep the original sealed and hash both.
Forensics Licence
The $299 Forensics licence covers 50 PCs. Personal ($99) and Business ($199) licences cover 2 and 10 PCs.
| Software Information | Univik Tally Data Forensic Analyzer |
| Version | 6.10 (Latest) |
| Licence | Free viewing, Forensics licence $299 for 50 PCs |
| System | Windows 10, Windows 11 and .NET Framework 4.8 and up |
| Evidence Read | Company folders in .500, .900 or .1800 format plus .001 backups, read-only |
| Hashes | MD5, SHA-1 and SHA-256 for every source file |
| Audit Trail | TallyPrime Edit Log versions, activities, usernames, dates and times |
| Report | PDF, CSV or HTML with a date and time stamp |
Questions
Reviewed by Nick Rogers Founder of Univik, 2013
Fact Checked
Nick Rogers reviewed this page on 6 October 2026. Mark Davis ran version 6.10 against 3 TallyPrime companies holding 327 MB of data. Tally facts come from Tally Solutions' help pages. Legal references come from the Ministry of Home Affairs text of the Bharatiya Sakshya Adhiniyam, 2023 and from ICAI guidance. The installer is signed, the software opens evidence read-only and every licence has a 30-day refund policy.
Review date: 6 October 2026
Read-Only EvidenceThree Hash TypesSigned InstallerSince 201330-Day Refund