Security and data boundaries

Understand brand scoping, OAuth secrets, human approval, and public-surface indexing controls.

Workspace isolation

Application reads and writes are scoped to the active brand and the authenticated user's membership. Connected accounts, buyers, conversations, orders, and catalog data remain inside that workspace boundary.

Secrets and connections

OAuth access and refresh tokens are encrypted before storage. Connection flows use a short-lived state value to protect the callback.

Public and private surfaces

Marketing and documentation pages are indexable. Authenticated product routes, API routes, onboarding, tokenized buyer pages, and embedded forms are excluded from search indexing.

Still need help?

Contact Miyara with the workspace and workflow you are setting up.

talha@miyara.app