| Tenant separation | CURRENT — EVIDENCE PACK PENDING | Tenant-level data separation is a current stated control. | Public policy and repository architecture exist; cross-tenant verification evidence is not yet packaged. | Application and Supabase configuration. | Capture isolation configuration and negative cross-tenant test evidence. |
|---|
| Encryption in transit | CURRENT — EVIDENCE PACK PENDING | TEMRIK states that encryption in transit is used. | Current Privacy Policy states encryption in transit; provider evidence is not yet packaged here. | Hosting, database, messaging and AI providers. | Capture current TLS/provider configuration evidence. |
|---|
| Encryption at rest | PROVIDER DEPENDENT | No universal verified at-rest encryption claim is made by this Trust Centre. | Database, storage and backup evidence has not yet been captured into the procurement pack. | Provider and storage configuration. | Verify provider configuration before upgrading this status. |
|---|
| Identity and access | CURRENT — EVIDENCE PACK PENDING | Authentication and access controls are part of the current service. | Public privacy/security material and application architecture; detailed evidence remains pending. | Supabase authentication and application configuration. | Document authentication methods, privileged access and account controls. |
|---|
| Role-based permissions | CURRENT — EVIDENCE PACK PENDING | Roles and permissions bound access and workflow authority where implemented. | Architecture/control documentation; scope varies by workflow. | Customer and workflow configuration. | Map roles to tested permissions for production workflows. |
|---|
| Human approval controls | CONFIGURABLE | Where configured, consequential actions can require authorised human review before release. | Human-control and Dispatcher Gate architecture exists; scope is workflow-specific. | Workflow configuration and external-action path. | Add approval-bypass and stale-approval tests. |
|---|
| Audit logging | CURRENT — EVIDENCE PACK PENDING | Audit logging is part of TEMRIK's stated current safeguards. | Privacy Policy states audit logging; event coverage, retention and integrity evidence remains to be packaged. | Application logging and storage configuration. | Map material event coverage and evidence. |
|---|
| Model provider dependencies | PROVIDER DEPENDENT | Privacy, retention, location and behaviour vary by the selected AI endpoint. | Current provider disclosure and model dependency architecture. | Selected provider, contract, account and region. | Maintain a verified production model/provider register. |
|---|
| Data retention | CURRENT — EVIDENCE PACK PENDING | Data is retained no longer than reasonably necessary, subject to legal, security and record-keeping requirements. | Current Privacy Policy; no universal fixed period is claimed. | Data class, agreement, law and provider behaviour. | Approve a data-class retention schedule. |
|---|
| Subprocessors | CURRENT — EVIDENCE PACK PENDING | TEMRIK publicly discloses current technology providers. | Supabase, Vercel, Twilio, OpenAI and Stripe are disclosed; precise role/location validation remains in progress. | Actual production services and configurations. | Maintain a reviewed register and change process. |
|---|
| Incident response | ROADMAP | TEMRIK has an incident-response approach but does not claim a tested programme. | Draft programme exists; no tabletop result is claimed. | Internal ownership, counsel and provider response paths. | Approve plan, assign owners and complete first tabletop. |
|---|
| Business continuity / DR | ROADMAP | No tested recovery programme, RTO or RPO is publicly claimed yet. | BCP/DR framework exists; restore evidence and targets remain pending. | Vercel, Supabase, model, messaging and other critical providers. | Verify backup configuration, run restore test and approve recovery targets. |
|---|
| Independent penetration testing | NOT CLAIMED | TEMRIK does not currently claim an independent penetration-test result. | No completed independent test was evidenced in this review. | Independent assessor and remediation programme. | Commission scoped testing and publish only an appropriate summary after remediation. |
|---|
| Certifications | NOT CLAIMED | TEMRIK does not currently claim SOC 2, ISO/IEC 27001, ISO/IEC 42001, HIPAA, PCI DSS or other independent certification unless verified. | Public non-claim position. | Future buyer demand, operating evidence and independent assurance. | Choose an assurance path only after core controls are operating and evidenced. |
|---|