Security is foundational at Tempo. We protect your workforce data with enterprise-grade controls.
Independent audit of security, availability, and confidentiality controls. Expected completion Q2 2026.
Information security management system certification. Planned for H2 2026.
Full compliance with EU General Data Protection Regulation including DPA availability.
California Consumer Privacy Act compliance for US data subjects.
TLS 1.3 in transit, AES-256 at rest. All data encrypted by default.
PBKDF2 password hashing, MFA/TOTP support, JWT sessions with 7-day expiry.
Role-based access (Owner, Admin, HRBP, Manager, Employee) with row-level security.
Every create, update, delete, login, and logout is recorded with user and IP context.
Tenant isolation via org-scoped queries. Cross-org data access is architecturally prevented.
Hosted on Vercel (edge) with Neon PostgreSQL (serverless). SOC 2 certified providers.
Dependency scanning, OWASP top 10 protection, rate limiting on sensitive endpoints.
72-hour breach notification per GDPR. Documented incident response procedures.