mykka.aiSTAGING

Security & Trust

How We Handle Your Data

CISOs ask hard questions. Here are honest answers.

Prompt content is never stored in full

Pretzel records which rule fired, which AI site, and which member triggered the event. For rules configured to report matched content, a brief excerpt of the matched text may be retained for audit purposes and is deleted on a rolling 90-day window. The full text of any prompt is never transmitted to or stored on our servers.

Encryption in transit and at rest

All API traffic uses TLS 1.3. Data at rest is encrypted with AES-256. Your org token is hashed with bcrypt — we cannot recover it.

SOC 2 Type II — in progress

We are actively working toward SOC 2 Type II certification, targeted for Q3 2026. Our security practices are designed to meet those controls now, before the audit. Interim controls documentation is available on request — contact security@mykka.ai.

GDPR & CCPA aligned by design

Data is stored in the EU by default (AWS eu-west-1, Frankfurt region). We are designed for GDPR and CCPA compliance. We are happy to sign a Data Processing Agreement (DPA) for enterprise customers — request one at privacy@mykka.ai.

Responsible disclosure

Found a vulnerability? Email security@mykka.ai. We aim to respond within 24 hours and fix within 7 days for critical issues. A formal bug bounty program is on our roadmap.