Security

Last updated: 14 July 2026. Temira is operated by M-Office Portal Limited (Federal Republic of Nigeria). Security is built into how Temira is engineered. This page describes the controls in place today and how to report a vulnerability. It is a summary, not a warranty; see our Terms.

Data protection in transit and isolation

Encryption in transit

All traffic to the Service is served over HTTPS/TLS. The app is HTTPS-only, with cleartext connections disabled and mixed content blocked.

Per-workspace isolation

Every workspace's data is isolated. Our data-access layer enforces workspace scoping on every query and fails closed — a query that isn't correctly scoped is rejected rather than allowed to cross workspaces.

Secrets handling

Your AI-provider keys and channel tokens are stored server-side, shown masked in the portal, and never sent to a browser. Payment and messaging secrets are held server-side only.

No cross-tenant AI

One workspace's content is never used to answer another business's assistant, and is not used to train shared models.

Authentication and access control

Password hashing

Passwords are stored only as salted PBKDF2 hashes (200,000 iterations) — never in plain text.

Two-factor authentication

Optional TOTP-based 2FA is available for accounts and for platform operators; we recommend enabling it.

Least-privilege operator roles

Platform staff access is governed by defined roles with the minimum permissions needed, and sensitive administrative areas can be restricted by IP allow-list and location checks.

Audit logging

Security-relevant actions — sign-ins and failed attempts, setting changes, payments, and administrative and support access — are recorded with timestamps and source IPs.

Platform hardening

Abuse & rate limiting

Requests are rate-limited and abusive patterns are throttled to protect availability and your data.

Support access is logged

Where an authorised operator accesses a workspace to help you — including signing in as your account for troubleshooting — that access is recorded in the activity log.

Payments

Card payments are processed by PCI-DSS-compliant providers (Paystack, Stripe). We do not store full card numbers.

Your controls

You can enable 2FA, set conversation retention, erase conversations and data permanently, export your data, and review your activity log at any time.

Data ownership, export and deletion

You own your content. You can export your leads, conversations and content, and delete conversations and other data permanently, from the portal. When you close your account we delete or de-identify your content within a reasonable period, except where retention is required by law. See the Privacy Policy for details.

Our posture on certifications

We engineer to widely recognised security principles (such as those underlying SOC 2 and ISO 27001) — least privilege, defence in depth, encryption, logging and isolation. We are honest about our status: we do not currently hold a third-party SOC 2 or ISO 27001 certification, and we will not claim one we do not have. If your organisation requires specific attestations or a security questionnaire, contact us.

Responsible disclosure

We welcome reports from security researchers. If you believe you have found a vulnerability, please email security@temira.net (or use the Contact page) with enough detail to reproduce it. Please:

Safe harbour: if you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research, and we will work with you. We do not currently operate a paid bug-bounty, but we gratefully acknowledge valid reports.

Incident response

We monitor for security issues and maintain an incident-response process. If a personal-data breach affecting you occurs, we will notify affected customers and, where required, the relevant authorities, within the timeframes applicable law requires.

No security is absolute

We work hard to protect your data, but no product, method of transmission, or method of storage is completely secure. This page describes controls, not guarantees; nothing here creates a warranty beyond what our Terms provide. You are responsible for securing your own credentials, devices, connected accounts, and how your team uses the Service.

Report a vulnerability: security@temira.net · General enquiries: Contact page