All traffic to the Service is served over HTTPS/TLS. The app is HTTPS-only, with cleartext connections disabled and mixed content blocked.
Every workspace's data is isolated. Our data-access layer enforces workspace scoping on every query and fails closed — a query that isn't correctly scoped is rejected rather than allowed to cross workspaces.
Your AI-provider keys and channel tokens are stored server-side, shown masked in the portal, and never sent to a browser. Payment and messaging secrets are held server-side only.
One workspace's content is never used to answer another business's assistant, and is not used to train shared models.
Passwords are stored only as salted PBKDF2 hashes (200,000 iterations) — never in plain text.
Optional TOTP-based 2FA is available for accounts and for platform operators; we recommend enabling it.
Platform staff access is governed by defined roles with the minimum permissions needed, and sensitive administrative areas can be restricted by IP allow-list and location checks.
Security-relevant actions — sign-ins and failed attempts, setting changes, payments, and administrative and support access — are recorded with timestamps and source IPs.
Requests are rate-limited and abusive patterns are throttled to protect availability and your data.
Where an authorised operator accesses a workspace to help you — including signing in as your account for troubleshooting — that access is recorded in the activity log.
Card payments are processed by PCI-DSS-compliant providers (Paystack, Stripe). We do not store full card numbers.
You can enable 2FA, set conversation retention, erase conversations and data permanently, export your data, and review your activity log at any time.
You own your content. You can export your leads, conversations and content, and delete conversations and other data permanently, from the portal. When you close your account we delete or de-identify your content within a reasonable period, except where retention is required by law. See the Privacy Policy for details.
We welcome reports from security researchers. If you believe you have found a vulnerability, please email security@temira.net (or use the Contact page) with enough detail to reproduce it. Please:
Safe harbour: if you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research, and we will work with you. We do not currently operate a paid bug-bounty, but we gratefully acknowledge valid reports.
We monitor for security issues and maintain an incident-response process. If a personal-data breach affecting you occurs, we will notify affected customers and, where required, the relevant authorities, within the timeframes applicable law requires.
We work hard to protect your data, but no product, method of transmission, or method of storage is completely secure. This page describes controls, not guarantees; nothing here creates a warranty beyond what our Terms provide. You are responsible for securing your own credentials, devices, connected accounts, and how your team uses the Service.