01
Read-only by design
VYRNA connects to your marketing platforms — Google Ads, Google Analytics 4, Meta Ads, LinkedIn Ads, Stripe — through secure OAuth 2.0 authorization, requesting read-only scopes only.
VYRNA never creates, edits, pauses, deletes, or otherwise modifies campaigns, ads, keywords, audiences, budgets, or account settings. There is no write path in the product.
You may disconnect any account at any time; disconnection immediately revokes VYRNA's future access.
02
The anti-fabrication doctrine
Most AI tools let a language model produce numbers. VYRNA doesn't. Every metric follows the same pipeline:
- Calculate — deterministic code computes every metric from your connected data. Same inputs, same number, every time.
- Narrate — the AI interprets computed numbers against your brand and objectives. It explains; it never invents.
- Validate — guardrails verify scope and significance before any claim ships. Insufficient data blocks the claim.
Zero numbers are generated by the language model. Every figure in a VYRNA verdict traces back to a real, auditable computation. If a number can't be computed honestly, VYRNA says so instead of showing it.
03
Workspace isolation
Customer data is logically isolated within individual VYRNA workspaces. Every data access is scoped to the requesting workspace, and access controls are enforced at the database and application layers to prevent cross-customer access.
04
AI governance
VYRNA uses Anthropic's Claude models to generate written analyses. Computed metrics, business context, and instructions may be sent to Anthropic's API solely to generate the outputs you request.
Your data is never used to train AI models. Not ours, not Anthropic's, not any third party's. AI providers are used under contractual terms that prohibit training on customer data.
A human always makes the final call. VYRNA proposes the verdict; it does not act autonomously on your accounts.
05
Infrastructure & encryption
- Encryption in transit — all traffic uses HTTPS/TLS.
- Encryption at rest — where supported by our infrastructure providers.
- OAuth credentials — managed by Nango; VYRNA does not store your platform passwords.
- Hosting — Supabase (database and backend) and Vercel (web infrastructure), with data hosted in Canada whenever reasonably possible.
- Monitoring — logging and monitoring for operational security.
06
Your controls
- Disconnect any connected account at any time — access is revoked immediately.
- Request deletion of all stored data at any time; deletion is completed within 30 days unless retention is required by law.
- Details on data handling live in our Privacy Policy.
07
Responsible disclosure
If you believe you have found a security vulnerability in VYRNA, please report it to hello@vyrna.ai. We investigate all good-faith reports and respond as quickly as possible.
Questions about security?
Contact us at hello@vyrna.ai.
Lilyane Technologies Inc. · Toronto, Ontario, Canada