mykka.ai

Security & Trust

How We Handle Your Data

CISOs ask hard questions. Here are honest answers.

Full prompts are never sent to us

Detection runs locally in the browser extension. When a rule matches, Pretzel records which rule fired, which AI site, and which member triggered it. If the rule is set to report matched content, a short excerpt of the matched text (for example the API key or card number that matched) is also sent and stored in your organisation’s audit log, where your admins can see it. Rules set to a lower report level send no excerpt. The full text of a prompt is never transmitted to or stored on our servers.

Encryption and token handling

API traffic uses HTTPS. Data at rest is encrypted by our database provider. Your organisation and admin tokens are stored only as bcrypt hashes — we cannot recover them.

Where your data lives

Our database is hosted on Neon (AWS us-east-1, United States). The backend runs on Render, the website on Vercel, sign-in is handled by Clerk, and application errors go to Sentry. If you use the AI Policy Assistant, your assistant messages are sent to the model provider (Anthropic, OpenAI or Groq). See the Privacy Policy for the full list. We do not currently offer EU data residency.

Retention

Scan counts and enforcement signals are deleted automatically after 90 days. Audit-log events, including any matched excerpts, are kept while your organisation account is active. During early access there is no automatic expiry on audit-log events; email privacy@mykka.ai and we will delete them on request.

Early access — what we have not done yet

Pretzel is in early access. We have not completed a third-party security audit such as SOC 2, and we do not yet have a standard Data Processing Agreement. If your organisation requires either, tell us at security@mykka.ai — it helps us decide what to prioritise.

Responsible disclosure

Found a vulnerability? Email security@mykka.ai. We will acknowledge reports as quickly as we can and prioritise critical issues.