Security & data handling
How TMP handles trust.
This page describes the current design and its boundaries; it is not a certification or security audit.
Last updated September 21, 2026
Private-test documentation · Legal review pending. Email contact details and operational claims must be verified before public release.
Where information goes
The intended hosted architecture uses Railway for the web/API and MDM services, Cloudflare D1 for application data, and the MDM service’s separate protocol database for enrollment and command state. Local builds may use development storage. Infrastructure-provider regions, contracts and backup settings must be verified before launch.
Account and controller access
Account authentication identifies the customer. The helper stores controller signing material in the operating system credential store; pairing codes are short-lived. A browser request should not authorize a weaker policy on its own. These controls require end-to-end verification on each supported platform.
Device communication
Production endpoints require HTTPS. Enrollment identities and command identifiers bind device responses to issued requests. TLS protects transport but does not mean all stored data is end-to-end encrypted: service systems need access to process commands and inventory.
Minimum necessary data
App inventory is metadata for classification and restrictions, not a browsing or message-content feed. Avoid credentials and full device identifiers in support attachments. Filtering-specific collection and retention must be documented and tested before enabling a managed browser or network extension.
Retention and deletion
Retention varies by operational purpose. A verified record-by-record schedule, backup expiry and deletion procedure are launch requirements. No fixed deletion deadline or independently audited security claim is made by this draft.
Report a vulnerability
Privately report a suspected issue using the support contact in your test invitation. Include reproducible steps without accessing another person’s records or testing destructively. A monitored public security contact is still required before release.