Security & Compliance

Platform passwords stay outside Myriad.
Each team's data stays separate.

Platform sign-in, product records and authorisation details are handled separately. This page explains what Myriad keeps, who can see it and where data is sent.

Account and data boundariesSECURITY / SCOPE
01 / BROWSER

Your browser

Platform sign-in and page access

02 / MYRIAD

Myriad services

Product records and processing results

03 / PLATFORM

Target marketplace

Listing data and marketplace feedback

Platform password boundaryBrowser ↔ marketplaceMyriad does not receive platform login passwords

Each team's data is kept separate

After sign-in, people can see only their own team's information. Myriad checks ownership again whenever anything is viewed, changed or deleted.

Your account decides what you can see

Myriad identifies your team from the account currently signed in. A page cannot choose another team, which prevents edited page content from exposing someone else's information.

Ownership is checked on every action

Before product, store or order information is viewed, changed or deleted, Myriad confirms that it belongs to the current team. Related information is checked as well.

Real two-team scenarios are checked repeatedly

Checks use information belonging to two teams at the same time and confirm that neither team can see or change the other's data.

Data outcomes are checked directly

Checks confirm not only that the page responds correctly, but also that the other team's original information remains unchanged.

Marketplace account boundary

Browser operations and marketplace accounts

Steps carried out on marketplace pages use the store account already signed in within the current browser. Stores are kept separate so accounts do not get mixed up.

  • Signed-in account

    Marketplace page operations take place in your own browser. Your platform password remains between you and the platform.

  • Network

    Access comes from your own network, down the same path as opening that page by hand. The network address, region and browsing pace the platform sees are all genuinely yours.

  • Stores kept separate

    Each store uses a separate browser window, so accounts do not get mixed up and the marketplace sees the actual way the store is being used.

Sign-in and extension security

Login passwords, signed-in status and extension authorisation serve different purposes, so Myriad protects them separately.

Login passwords

Passwords are protected in a form that cannot be reversed. The original password is never stored, returned by a page or written into activity records.

The same check runs even when a phone number does not exist, making it harder to probe which numbers are registered.

Signed-in status

Myriad keeps only an unusable verification result, not the original value that could be used to sign in.

Myriad checks that sign-in is still valid on every visit. After sign-out or expiry, the previous signed-in status can no longer be used.

Data transfer and service protection

Encrypted connections throughout

The website, seller workspace and company administration area can be reached only through encrypted connections. No unencrypted entry point is provided.

Protection against page misuse

Browser protections are enabled consistently to reduce the risk of pages being embedded by another site, content being disguised or visit details being exposed unexpectedly.

Unusually frequent access is limited

Access that is too frequent over a short period is limited. Marketplace notifications follow separate rules so legitimate business activity is not blocked.

Repeated notifications take effect once

If the same external notification arrives more than once, it takes effect only once.

Updates do not interrupt service

A new version takes over only after it is confirmed to be working. Work already under way is allowed to finish, so routine updates need no service outage.

Sensitive information is kept separately

Marketplace authorisation details, store keys and internal service passwords are not placed in program files and do not appear in activity records.

Where your data goes

The table lists the external services that receive data in current features, together with the data scope and purpose.

Recipient What they receive Why
Intelligent processing provider Product titles, descriptions, category paths, attribute values Used to choose categories, complete attributes and rewrite content. Contains no account details, contact information or order data
Event notification address you choose Notification content you chose to receive Chosen by the current team and removable at any time
Target e-commerce platforms Product data selected for listing Publishing the product to the target marketplace

Found a security issue?

Email us directly and explain how the issue appeared, when it happened and what it affected. We respond within two business days, address confirmed issues as quickly as we can and tell you the outcome. Please don't disclose publicly first.

contact@yuhaninfo.cn