Authenticated access
Mirynna verifies Firebase/Google Identity tokens and checks organization membership before protected cloud routes are used.
Mirynna combines identity controls, server-side integration credentials, encrypted provider tokens, environment separation, and approval-aware workflows. This page describes current product controls and clearly separates them from controls still being completed for public launch.
Mirynna verifies Firebase/Google Identity tokens and checks organization membership before protected cloud routes are used.
Google Workspace and Shopify authorization tokens are encrypted before database storage. Provider application secrets remain server-side.
Consequential connected-service actions can be prepared first and executed only after an authorized Mirynna user approves them.
Mirynna's cloud API runs on Google Cloud. Application secrets are delivered through Google Cloud Secret Manager, identity is validated server-side, and development and production use separate Google Cloud projects.
External browser and API traffic uses HTTPS. Google Cloud-managed services provide encryption at rest for their underlying managed storage; Mirynna additionally encrypts stored Google Workspace and Shopify authorization tokens at the application layer.
Database credentials, AI provider keys, Google OAuth credentials, Shopify app credentials, and encryption keys are not shipped to the browser.
Mirynna checks active organization membership and role before organization-scoped data or admin operations are allowed.
Connected Google content is retrieved as needed for user-facing workflows and treated as untrusted content rather than instructions.
Approval workflows provide a review point before supported high-impact edits or external actions are executed.
Mirynna is completing formal data-retention enforcement, protected-data access auditing, mandatory Shopify privacy webhooks, staff MFA/access standards, incident-response procedures, a documented data-loss-prevention program, and additional protections required for Google Workspace restricted scopes. These items will be marked complete only after they are implemented and verified.
Mirynna does not currently claim SOC 2, ISO 27001, HIPAA, PCI certification, or other third-party security certifications on this website. Any future certification will be published only after it is formally achieved.
To report a suspected security vulnerability or security incident involving Mirynna, contact security@mirynna.com. For general support, contact support@mirynna.com or call +1 (702) 789-7604.