MYRAKELL MYRAKELL Find Opportunities. Grow Businesses.
Features Pricing FAQ Security About Us Contact Us
Sign In Request Free Demo
MYRAKELL security

Security at MYRAKELL

Protecting your account, workspace, and business information.

MYRAKELL is designed with security controls intended to protect user accounts, business information, Agency workspaces, and the systems used to provide the MYRAKELL platform.

We use multiple layers of application security, including access controls, protected sessions, encrypted credential storage, request protections, secure image handling, browser security controls, AI data minimization, and automated security testing.

1. Account & Password Security

MYRAKELL protects user accounts through safeguards designed to reduce unauthorized access.

Passwords are stored using salted, one-way password hashing and are not stored as readable passwords.

Password-reset links are randomly generated, time-limited, and invalidated after successful use.

MYRAKELL also applies login rate limits and temporary account lockouts to help protect against repeated password-guessing attempts.

2. Secure Sessions & Connections

MYRAKELL uses signed, HttpOnly browser sessions with inactivity timeouts.

Production session cookies are configured with the Secure flag for transmission over HTTPS. Production environments also require dedicated session-secret configuration rather than relying on hard-coded development credentials.

MYRAKELL production environments are configured to enforce HTTPS and use HTTP Strict Transport Security (HSTS).

3. Workspace & Access Protection

MYRAKELL uses role-based permissions to control access to Platform features and workspace actions.

Agency-scoped information is restricted according to the user's authorized Agency association. MYRAKELL uses fail-closed tenant validation so users without a valid Agency association cannot gain Agency workspace access simply because an Agency relationship is missing.

Cross-Agency access is restricted to help prevent one Agency from accessing another Agency's workspace information.

Business Owner access is managed through separate ownership and authorization workflows.

Authorized MYRAKELL Platform administrators may have broader access when reasonably necessary to operate, administer, secure, and support the Platform.

4. Request & Browser Security

Authenticated state-changing actions are protected using session-bound Cross-Site Request Forgery (CSRF) protections.

MYRAKELL also applies browser security controls including:

  • Content Security Policy (CSP)
  • MIME-sniffing protection
  • Same-origin framing restrictions
  • Referrer-policy controls
  • Browser permissions restrictions
  • Production HTTPS enforcement
  • HSTS in production

These controls are intended to reduce common browser and web-application security risks.

5. Integration Credential Protection

Sensitive integration credentials stored by MYRAKELL are protected using authenticated encryption.

This includes supported credentials used for email delivery and Platform integrations.

MYRAKELL does not intentionally use plaintext or reversible Base64 encoding as a credential-storage mechanism. Legacy credentials that do not satisfy current secure-storage requirements are rejected and must be securely entered again.

6. Secure Branding Uploads

Agency branding uploads are restricted to authorized users.

MYRAKELL validates supported images using their actual decoded image format rather than relying solely on filenames or browser-provided file types.

Supported branding uploads currently include PNG, JPEG, and WEBP images. Unsupported formats such as SVG are rejected.

Accepted images are decoded and re-encoded before storage. MYRAKELL also applies file-size, image-dimension, and total-pixel restrictions to branding uploads.

7. Artificial Intelligence & Data Minimization

MYRAKELL uses Google Gemini for certain AI-assisted Platform features, including business analysis, recommendations, proposal generation, and outreach-content generation.

MYRAKELL's AI processing controls limit Gemini prompts to approved business and derived market-analysis information required for the applicable functionality.

Current controls are designed to exclude categories such as:

  • Personal contact information
  • CRM notes and messages
  • Uploaded files
  • Raw website content
  • Account credentials
  • Raw third-party API payloads

Business-supplied information included in AI prompts is treated as untrusted reference information and separated from application instructions to reduce prompt-manipulation risks.

MYRAKELL currently uses Google's paid Gemini API service. Additional information regarding AI processing is available in our Privacy Policy.

8. AI-Generated Content & Human Review

Artificial intelligence may produce inaccurate, incomplete, outdated, or otherwise unsuitable information.

AI-generated outreach remains editable so authorized users can review and modify generated material before using it for external communications.

MYRAKELL also validates applicable generated output before accepting it into Platform workflows. Failed or malformed AI generation is handled separately from valid generated content and does not automatically overwrite previously saved valid content.

Users remain responsible for reviewing AI-generated material before relying upon, publishing, sending, or otherwise using it.

9. Security Testing & Activity Records

MYRAKELL maintains automated regression testing covering important application-security boundaries, including authentication, authorization, role-based access, Agency tenant isolation, Business Workspace access, CSRF protection, credential storage, branding-upload validation, browser security controls, and AI data boundaries.

MYRAKELL also records selected account, authentication, administrative, and workspace events for operational and security review.

Not every Platform action is necessarily recorded as a security audit event.

10. Our Approach to Security

Security is an ongoing process.

MYRAKELL may update its safeguards as the Platform evolves, new functionality is introduced, service providers change, or new risks are identified.

No internet-based service can guarantee absolute security. Users are also responsible for protecting their login credentials and devices and for promptly reporting suspected unauthorized account activity.

MYRAKELL relies on selected third-party infrastructure and service providers for portions of the Platform. Those providers maintain their own security controls, terms, privacy practices, and operational responsibilities.

11. Security Certifications & Compliance

MYRAKELL does not currently represent itself as SOC 2 certified, PCI DSS certified, HIPAA compliant, or certified under another formal security framework unless and until the applicable requirements have been independently established.

The safeguards described on this page refer to security controls implemented for the MYRAKELL Platform and should not be interpreted as a representation of independent certification.

Report a Security Concern

If you believe you have discovered a security vulnerability or suspect unauthorized activity involving MYRAKELL, please contact us promptly.

Security Contact: bend7551@gmail.com

Please provide enough information for us to understand and investigate the issue, but do not send passwords, API keys, access tokens, or other sensitive credentials by email.

MYRAKELL
Operated by MYRAKELL LLC
MYRAKELL.com
1633 Antigua Lane
Manteca, CA 95337
MYRAKELL MYRAKELL

Find opportunities. Grow businesses.

Product

Features Pricing Request Demo

Company

About Us Contact Us

Resources

FAQ Security

Legal

Privacy Policy Terms of Service Cookie Policy

Account

Sign In
© 2026 MYRAKELL. All rights reserved. · Find Opportunities. Grow Businesses.