Security is a foundation of the Temble platform. This page describes the practices Nesta Business LLC uses to protect the confidentiality, integrity and availability of the Services and the information entrusted to us.
Temble is designed with defense in depth. Controls are layered across our application, infrastructure and operations so that a failure in any one layer does not compromise the platform as a whole. This page summarizes the practices in place today and is updated as the program evolves.
Temble runs on reputable cloud infrastructure with network isolation, hardened machine images, and configuration managed as code. Changes go through peer review and automated checks before deployment.
We centralize application, infrastructure and security logs. Alerts route to on-call engineers for triage. Baselines and anomaly detection help us identify unusual behavior early.
We maintain an incident response process covering detection, containment, eradication, recovery and post-incident review. Where an incident affects customer data and notification is required, we notify affected customers in line with applicable law and our contractual obligations.
We welcome reports from the security community. If you believe you have found a vulnerability in the Services, please email {{Support Email}} with the subject line “Security disclosure”. Please provide enough detail to reproduce the issue and avoid actions that could harm the platform or its users (for example, denial of service, data exfiltration or accessing accounts that are not your own).
For general security questions, visit our Contact page. Sensitive reports should be sent to {{Support Email}} with “Security” in the subject line.