Security at Temper: Vulnerability Disclosure Policy

Help us keep the marketplace moving.

At Temper, we empower people to work on their own terms, and that freedom relies on a foundation of security. Whether it’s a hospitality shift or a logistics contract, the data of our workers and businesses is our top priority. While we do not operate a formal, high-volume bug bounty program, we value the expertise of the security community and provide discretionary rewards for reproducible reports that help us stay secure. We aim to acknowledge every report within 5 business days and to keep you updated as we investigate.

1. Safe Harbour (our promise to you)

If you act in good faith and within the bounds of this policy, and do not harm our users or services, Temper will not initiate legal action against you. We view your research as a collaborative effort to protect the platform.

2. The Rules of Engagement

To qualify for a reward and remain under Safe Harbour protection, you must:
  • Avoid Harm: Do not modify, delete, or download more data than is strictly necessary to prove a vulnerability.
  • Privacy First: You may only access your own data or use two test accounts you own to demonstrate cross-account vulnerabilities (IDOR).
  • Personal data: If you encounter any personal data (e.g. another user's details), stop, do not download or store it, and tell us immediately in your report. We treat any incidental access under our data-protection obligations.
  • Confidentiality: Do not disclose the issue to anybody else until Temper has resolved it and provided written confirmation.

3. In Scope

This policy covers systems Temper operates directly:

temper.works and its subdomains, the Temper web and mobile apps, and our public API. Anything hosted by a third party (e.g. our SaaS vendors, marketing tools, or services on domains we don't control) is out of scope.

4. Out of Scope (What We Don't Reward)

We do not reward "best practice" findings that lack a clear exploit path, including:

— Automated scanner reports, banner grabbing or AI-generated reports submitted without a demonstrated, reproducible exploit.
—  DMARC/SPF/Email misconfigurations or Social Engineering.
—  Denial of Service (DoS/DDoS) attacks.
—  Clickjacking, Self-XSS, or Logout CSRF.

5. How to report

Help us act fast by including:

  • Affected asset — the URL, endpoint, or app screen.
  • Vulnerability type — e.g. IDOR, XSS, auth bypass.
  • Steps to reproduce — clear enough for us to follow start to finish.
  • Proof of concept — a request/response, screenshot, or short clip.
  • Impact — what an attacker could actually do, and your view on severity.

Reports in English are easiest for us to triage quickly. A clear, well-structured report also helps us assess any discretionary reward.

6. Rewards & Payouts

Rewards are entirely discretionary and based on the Severity of the impact and Quality of the report. There is no guaranteed payout, and recognition may take the form of a reward or public thanks.

  • Priority: We focus on vulnerabilities that could compromise user data or bypass core platform logic.
  • Eligibility: You must not be located in, or resident of, any country or region subject to applicable EU or UN sanctions.

Discovered anything?

Please share your report, following the above instructions, with us.