Skip to content

security

The questionnaire, answered with current controls.

Temja separates deployed controls from production gates and integration pilots.

This page is the short form

The full questionnaire — residency and encryption, tenant isolation, retention and erasure, our classification under the AI Act, the boundaries of the product, and responsible disclosure — is answered in full on the English security page. Our contract, processing agreement and privacy notice are English-language documents.

Read the full security answers

Trusted evidence writes

Clients send raw answers and command ids. The server derives scores, timestamps, certificates, hashes, and audit entries.

Identity status

Verified email/password is available. Tenant-admin MFA, SSO, and SCIM remain explicit production or Enterprise acceptance gates.

Audit-chain boundary

The chain is append-only and HMAC-signed. It is not independently anchored against an operator holding the signing key.

Participation, not certification

Temja records training measures and demonstrated outcomes. It is not legal advice or an accredited certification body.

Retention and erasure

We propose a five-year default and write the period you actually need into your contract. Deleting on that schedule is a manual operation today — the retention jobs and their restore tests are unfinished.

An erasure request removes or de-identifies profile data while leaving the append-only audit chain intact. We work each request by hand; the automated de-identification path is not built.

Responsible disclosure

Report a vulnerability to the address below. We operate a 90-day coordinated disclosure window and keep you credited and informed.

security@temja.eu · /.well-known/security.txt

Who processes your data

These providers process data on Temja's behalf. Production use requires a current data-processing agreement with each one, and this is the list our data processing agreement authorizes as sub-processors.

  • Firebase / Google Cloud

    Role
    Authentication, database, hosting, bot protection (reCAPTCHA Enterprise)
    Region
    europe-west (EU)
  • Resend

    Role
    Outbound transactional email (verification, welcome, notices)
    Region
    EU (Ireland)
  • Migadu

    Role
    Inbound email for temja.eu mailboxes
    Region
    EU / Switzerland (adequacy)
  • Stripe

    Role
    Subscription billing, checkout, and invoicing when you subscribe
    Region
    EU entity; may process billing data outside the EU

Your national authorities · Ireland

The bodies that supervise this in your market, as we hold them. The AI Act authority landscape is still settling, so tell us if a designation has moved and we will correct it here.

Data protection authority
Data Protection Commission (DPC)
AI Act authority
15 designated competent authorities (S.I. 366/2025); Oifig IS na hÉireann is pending a ministerial establishment-day order
Employee consultation
Information & Consultation ForumUnder the Employees (Provision of Information and Consultation) Act 2006, staff can require an information-and-consultation forum; there is no German-style co-determination veto.