Skip to main content

No product access needed

Prepare a security review

Document the data, credentials, people, retention needs, and deployment boundary for one evaluation workflow.

Expected outcome

The security conversation is grounded in the exact workflow and evidence the evaluation will use.

You can use this public guide without a Tempera account, product credential, or private workspace. Product access begins only after private onboarding.

Before you start

  • The evaluation workflow and data boundary
  • Owners for integration, review, and security questions

Steps

  1. 01

    List the data involved

    Identify page content, screenshots, browser state, trace fields, reviewer notes, and any sensitive values.

  2. 02

    List the credentials involved

    Identify who owns each credential, where it is stored, what it can do, and how it will be revoked.

  3. 03

    Set review and retention needs

    Agree who may review evidence, what must remain redacted, how long evidence is needed, and what must be exported or deleted.

  4. 04

    Request the matching deployment information

    Ask the Tempera onboarding team for the current architecture and control evidence that applies to the proposed hosted or private environment.

What success looks like

  • A data-flow sketch for the selected workflow
  • A credential owner and revocation plan
  • A written review and retention boundary
  • A list of unanswered questions for the onboarding team

If something is blocked

  • If the workflow cannot be explained without broad platform claims, narrow it to the first browser session and trace.
  • If a required control is not documented for the selected environment, treat it as an open evaluation item rather than an assumed capability.