1. Separate domains
Public website
Marketing, pricing, security, legal information and one limited business-enquiry endpoint. Internal payroll and billing APIs are not routed through this host.
Secure workspace
Verified authentication, company-scoped product access and protected billing actions where enabled.
2. Verified self-service admission
A verified OpenID Connect identity may create one Zimbabwe company owner workspace. Authentication does not grant access to any other company, and every later request is resolved against the bound company membership and role.
3. Company isolation and least privilege
Commercial membership and payroll operations are company-scoped. Application checks and restrictive database relationships are designed to reject cross-company access. Sensitive functions also require roles and enabled features.
4. Preview and paid entitlements
The two-employee preview limit is enforced on the server, including concurrent entry and import paths. Paid-only functions do not activate from a browser return URL. Plan access and employee capacity are derived from server-side subscription state updated by a valid signed payment webhook.
5. Card controls where enabled
Card checkout is available only when Temric has configured it and the secure workspace shows it as available. The browser may then redirect to hosted checkout, but a successful return page is not trusted as payment evidence. Activation depends on signed payment-provider confirmation and recorded server-side state.
6. Manual-payment controls where enabled
Bank Transfer or EcoCash instructions are available only when configured and issued through an authorised Temric channel. Each enabled request receives a unique reference. Transaction references and uploaded proof are treated as private payment evidence, restricted by company and billing-administrator checks. Submission does not automatically activate access; a separate authorised decision records verification.
7. Sensitive data and review history
Selected company, employee and payment-proof fields are encrypted before storage. Temric separates draft preparation from reviewed history, and audit records preserve material access, payroll and activation events.
8. Public form controls
The sales form validates strict lengths and formats, requires consent, rejects a honeypot and unrealistically fast submissions, checks origin, limits body size and rate-limits attempts. It creates no company, membership, payroll or payment record.
9. Boundaries
Marketing pages do not expose internal payroll APIs. Public workspace creation is limited to verified identities and one owner workspace per identity. Live payroll posting, UAT posting, Zambia payroll and Lomake UAT imports remain outside the active route set.
10. Reporting a concern
Use the public business form, start the description with “Security report” and do not include exploit code, credentials or employee data. Customers should use their governed support channel.