TEMRIK TRUST CENTRE

Trust should be evidenced, not implied.

TEMRIK distinguishes current controls, verified controls, provider dependencies, configurable architecture, roadmap items and certifications that are not claimed. This page is designed for procurement, security, privacy and legal review.

01–02

Trust overview / verification matrix

Show the status. Show the dependency. Show the evidence.

A status is not upgraded to VERIFIED CURRENT until TEMRIK has reviewed evidence for the actual production control. Architecture direction, provider capability and public policy language are not treated as equivalent to tested control evidence.

Tenant separation

CURRENT — EVIDENCE PACK PENDING
Current claim
Tenant-level data separation is a current stated control.
Evidence
Public policy and repository architecture exist; cross-tenant verification evidence is not yet packaged.
Dependency
Application and Supabase configuration.
Next verification
Capture isolation configuration and negative cross-tenant test evidence.

Encryption in transit

CURRENT — EVIDENCE PACK PENDING
Current claim
TEMRIK states that encryption in transit is used.
Evidence
Current Privacy Policy states encryption in transit; provider evidence is not yet packaged here.
Dependency
Hosting, database, messaging and AI providers.
Next verification
Capture current TLS/provider configuration evidence.

Encryption at rest

PROVIDER DEPENDENT
Current claim
No universal verified at-rest encryption claim is made by this Trust Centre.
Evidence
Database, storage and backup evidence has not yet been captured into the procurement pack.
Dependency
Provider and storage configuration.
Next verification
Verify provider configuration before upgrading this status.

Identity and access

CURRENT — EVIDENCE PACK PENDING
Current claim
Authentication and access controls are part of the current service.
Evidence
Public privacy/security material and application architecture; detailed evidence remains pending.
Dependency
Supabase authentication and application configuration.
Next verification
Document authentication methods, privileged access and account controls.

Role-based permissions

CURRENT — EVIDENCE PACK PENDING
Current claim
Roles and permissions bound access and workflow authority where implemented.
Evidence
Architecture/control documentation; scope varies by workflow.
Dependency
Customer and workflow configuration.
Next verification
Map roles to tested permissions for production workflows.

Human approval controls

CONFIGURABLE
Current claim
Where configured, consequential actions can require authorised human review before release.
Evidence
Human-control and Dispatcher Gate architecture exists; scope is workflow-specific.
Dependency
Workflow configuration and external-action path.
Next verification
Add approval-bypass and stale-approval tests.

Audit logging

CURRENT — EVIDENCE PACK PENDING
Current claim
Audit logging is part of TEMRIK's stated current safeguards.
Evidence
Privacy Policy states audit logging; event coverage, retention and integrity evidence remains to be packaged.
Dependency
Application logging and storage configuration.
Next verification
Map material event coverage and evidence.

Model provider dependencies

PROVIDER DEPENDENT
Current claim
Privacy, retention, location and behaviour vary by the selected AI endpoint.
Evidence
Current provider disclosure and model dependency architecture.
Dependency
Selected provider, contract, account and region.
Next verification
Maintain a verified production model/provider register.

Data retention

CURRENT — EVIDENCE PACK PENDING
Current claim
Data is retained no longer than reasonably necessary, subject to legal, security and record-keeping requirements.
Evidence
Current Privacy Policy; no universal fixed period is claimed.
Dependency
Data class, agreement, law and provider behaviour.
Next verification
Approve a data-class retention schedule.

Subprocessors

CURRENT — EVIDENCE PACK PENDING
Current claim
TEMRIK publicly discloses current technology providers.
Evidence
Supabase, Vercel, Twilio, OpenAI and Stripe are disclosed; precise role/location validation remains in progress.
Dependency
Actual production services and configurations.
Next verification
Maintain a reviewed register and change process.

Incident response

ROADMAP
Current claim
TEMRIK has an incident-response approach but does not claim a tested programme.
Evidence
Draft programme exists; no tabletop result is claimed.
Dependency
Internal ownership, counsel and provider response paths.
Next verification
Approve plan, assign owners and complete first tabletop.

Business continuity / DR

ROADMAP
Current claim
No tested recovery programme, RTO or RPO is publicly claimed yet.
Evidence
BCP/DR framework exists; restore evidence and targets remain pending.
Dependency
Vercel, Supabase, model, messaging and other critical providers.
Next verification
Verify backup configuration, run restore test and approve recovery targets.

Independent penetration testing

NOT CLAIMED
Current claim
TEMRIK does not currently claim an independent penetration-test result.
Evidence
No completed independent test was evidenced in this review.
Dependency
Independent assessor and remediation programme.
Next verification
Commission scoped testing and publish only an appropriate summary after remediation.

Certifications

NOT CLAIMED
Current claim
TEMRIK does not currently claim SOC 2, ISO/IEC 27001, ISO/IEC 42001, HIPAA, PCI DSS or other independent certification unless verified.
Evidence
Public non-claim position.
Dependency
Future buyer demand, operating evidence and independent assurance.
Next verification
Choose an assurance path only after core controls are operating and evidenced.

03

Security architecture

The control plane sits between information and action.

TEMRIK's security architecture separates tenant and identity boundaries, role and tool permissions, model access, the Dispatcher Gate, human authority and audit evidence. The full architecture remains on /ai-security.

Tenant + identity boundary
Role + tool permissions
Dispatcher Gate + human authority
Audit + action evidence
Explore AI security architecture →

04

Data handling

Deployment-specific, not a universal promise.

Customer and end-user data may include identity/contact details, enquiry and workflow information, configured business rules, account/security events, communications and technical information required to operate the service.

The current Privacy Policy discloses Supabase, Vercel, Twilio, OpenAI and Stripe. Provider access, region, retention and data categories depend on the actual workflow and provider configuration. TEMRIK does not claim universal zero retention or that data never leaves a region.

The Privacy Policy currently states that primary Supabase database infrastructure is hosted in Ireland, EU. Other processing locations remain provider/configuration dependent.

Read the Privacy Policy →

05

Model providers

Current use is separated from architecture examples.

Current provider disclosed

OpenAI

The current Privacy Policy identifies OpenAI for AI-assisted enquiry triage. Exact endpoint, retention, region and account controls require deployment verification.

Configurable / architecture examples

Anthropic, Gemini, Azure-hosted models, AWS-hosted models and private/open models may appear in TEMRIK architecture material. Their appearance does not mean they are all current production integrations.

06

Subprocessor register

Public disclosure with verification boundaries.

This register reflects current public disclosures. It does not guess a processing region where TEMRIK has not verified the relevant service configuration.

Supabase

Purpose

Database, authentication and backend infrastructure

Data category

Account, customer/workflow and operational data as configured

Location / region

Primary database region publicly stated as Ireland, EU; wider provider processing must be verified per service

Role

Technology service provider

Change status

CURRENT — EVIDENCE PACK PENDING

Vercel

Purpose

Website and application hosting

Data category

Application requests and operational/technical data as applicable

Location / region

VERIFICATION PENDING — no single region is inferred

Role

Hosting provider

Change status

CURRENT — EVIDENCE PACK PENDING

Twilio

Purpose

SMS messaging

Data category

Message/contact data required for configured workflows

Location / region

VERIFICATION PENDING

Role

Messaging provider

Change status

CURRENT — EVIDENCE PACK PENDING

OpenAI

Purpose

AI-assisted enquiry triage in the current public disclosure

Data category

Scoped workflow/enquiry content required for the configured AI task

Location / region

VERIFICATION PENDING — endpoint/account dependent

Role

AI model/service provider

Change status

CURRENT — EVIDENCE PACK PENDING

Stripe

Purpose

Payment infrastructure — publicly disclosed as test-mode only

Data category

Test/payment-flow data within the configured boundary

Location / region

VERIFICATION PENDING

Role

Payment infrastructure provider

Change status

CURRENT — EVIDENCE PACK PENDING

Target change governance: maintained register, named owner, quarterly review, provider-onboarding review and a contractual material-change/customer-notification model once approved. TEMRIK does not claim that customer notification mechanics are already implemented.

07

Human authority

AI may prepare. AI may analyse. AI may recommend.

Consequential authority remains with authorised people where the workflow is configured to require it.

Proposed action is separate from permission to release it.

An authorised person can approve, reject, amend, request more information or escalate where supported.

Higher-consequence workflows should bind approval to the evidence and exact action being released.

The model is not the authority source.

08

Auditability

Operational evidence, not private chain-of-thought.

TEMRIK's audit architecture is designed around reconstructing material work: actor, workflow, evidence, policy result, approval, released action and outcome.

Actor
Workflow
Evidence
Policy result
Approval
Action
Outcome
Exception

No storage-duration, immutability, tamper-proof or universal event-coverage guarantee is implied unless separately verified.

09

Incident response

Current posture

Current status
ROADMAP / operating approach documented.
Policy
Draft programme; approval pending.
Tabletop
Not yet evidenced.
Notification
Assess applicable contractual and legal obligations; counsel-dependent where material.

10

BCP / DR

Recovery evidence is being built.

Backup configuration
VERIFICATION PENDING
Restore test
NOT YET EVIDENCED
RTO
TO BE APPROVED
RPO
TO BE APPROVED
Failover
PROVIDER / WORKFLOW DEPENDENT
Business continuity plan
IN REVIEW

11

Penetration testing

Planned, not represented as completed.

Independent penetration testing: planned / not yet evidenced.

Recommended first scope: cross-tenant access, authentication, privilege escalation, APIs, integrations, tool authority, Dispatcher Gate/approval bypass, agent permissions, data leakage and audit integrity.

12

Certification status

No certification is inherited from architecture or providers.

TEMRIK does not currently claim SOC 2, ISO/IEC 27001, ISO/IEC 42001, HIPAA, PCI DSS or any other independent certification unless verified for TEMRIK's own applicable scope.

SOC 2

NOT CLAIMED

ISO/IEC 27001

NOT CLAIMED

ISO/IEC 42001

NOT CLAIMED

HIPAA

NOT CLAIMED

PCI DSS

NOT CLAIMED

Roadmap: establish operating controls and evidence first, complete independent technical testing, then choose SOC 2 or ISO/IEC 27001 based on customer demand. ISO/IEC 42001 can be evaluated after AI management-system controls are mature.

13

Procurement documentation

What a buyer can request — and what is still being built.

DPA

PLANNED

Security questionnaire

IN REVIEW

Incident response policy

IN REVIEW

BCP / DR summary

IN REVIEW

Penetration-test summary

NOT AVAILABLE

Procurement principle

Do not ask the buyer to trust the claim. Show the status. Show the dependency. Show the evidence.

Sensitive evidence — raw logs, detailed configuration, full penetration-test findings, exploit detail, secrets or customer-specific records — is not public. Appropriate evidence may be supplied during procurement under suitable confidentiality controls.

Request procurement material