Tempora
Back to home

Security & Trust

Last updated: 24 September 2026

Tempora handles scheduling and workforce data for staffing agencies, including employee contact details and certification records. This page summarizes the controls we have in place today. It's a plain-language summary for prospects and buyers. Our full internal security documentation, including known gaps we're actively working through, is available on request.

Access control & MFA

Every account belongs to an agency through a role (owner, admin, or employee), and every API request is checked against that role before any data is read or changed. Optional two-factor authentication (TOTP) is available on every account, and once enrolled it's enforced at every layer (login, dashboard, and API), not just the login screen.

Encryption in transit and at rest

All traffic to Tempora is encrypted (HTTPS/TLS), enforced with HSTS. Data at rest is encrypted at the infrastructure level by our database provider (Supabase/PostgreSQL).

Tenant isolation

Every agency's data (employees, shifts, certifications, billing) is scoped and isolated so no other agency using Tempora can see it. This isolation is enforced on every single query, not just at the UI layer.

Session management

Sessions automatically expire after a period of inactivity, and any user can revoke all of their active sessions from Settings at any time. Useful after a lost device or a shared computer.

Audit logging & GDPR erasure

Team management actions (invites, role changes, removals) are recorded in an audit log administrators can review. Personal data erasure requests, for a single employee or an entire agency closing its account, go through a tracked, auditable approval and completion process.

Dependency & platform security

Automated weekly dependency scanning flags known vulnerabilities in our software supply chain, and every change to Tempora goes through automated type-checking, linting, and a full build before it can ship.

Subprocessors

We rely on a small set of well-known infrastructure providers, each with a specific, limited role:

  • Supabase — authentication and database hosting.
  • Vercel — application hosting and edge network.
  • Stripe — billing and payment processing; Tempora never sees or stores card details.
  • Resend — transactional email delivery.
  • Cloudflare R2 — storage for uploaded certification files and sick-leave medical certificates.
  • Sentry — error tracking.
  • Google (Gemini API) — answers to questions asked in the in-app assistant; it can't see your agency's records.
  • Plausible Analytics — cookieless website statistics, hosted in the EU; no personal data.

Compliance status

Tempora has not yet completed a SOC 2 audit or equivalent third-party certification. Our GDPR-relevant practices (data subject access and erasure, subprocessor disclosure, and data minimization) are described in our Privacy Policy. A Data Processing Agreement is available for enterprise customers. Contact us to request one.

Reporting a security issue

If you believe you've found a security vulnerability in Tempora, please report it responsibly to office@bytetech.ee. We ask that you not publicly disclose the issue until we've had a reasonable opportunity to investigate and address it.

Questions

For a detailed security questionnaire, a signed DPA, or anything not covered here, reach out via our Contact page.