Security

Last updated August 15, 2026

An overview of how MakrBee protects your account and the business data you enter. For how we collect, use, and share information, see our Privacy Policy. This page describes our security posture at a high level and deliberately omits sensitive infrastructure detail.

Encryption

  • All traffic to and from MakrBee is encrypted in transit (HTTPS/TLS).
  • Particularly sensitive credentials (for example, third-party marketplace access tokens) are encrypted at rest using industry-standard symmetric encryption, with the encryption key stored and managed separately from the encrypted data itself.

Authentication and Access Control

  • Passwords must meet minimum length and complexity requirements, can't reuse recent passwords, and expire periodically.
  • Accounts are temporarily locked after repeated failed sign-in attempts.
  • Two-factor authentication (an authenticator app, not email or SMS) is available to every account, and is part of our ongoing rollout of mandatory protection for business owner and administrator accounts.
  • Access within a business account is role-based — you control which teammates can view or manage financial data, inventory, purchases, and other areas.
  • Every business's data is isolated from every other business's data.

Monitoring

Security-relevant events — sign-ins, password changes, account lockouts, and administrative actions — are recorded to a centralized audit trail that application users, including our own team, cannot edit or delete.

Secure Development

Every code change runs through automated testing, dependency vulnerability scanning, static security analysis, and secret-detection scanning before it ships.

Payment Data

Subscription payments are processed by Stripe. MakrBee never collects or stores your full card number.

Responsible Disclosure

If you believe you've found a security vulnerability in MakrBee, please email support@makrbee.com with details. We take security reports seriously and will investigate promptly — please give us a reasonable opportunity to respond before disclosing an issue publicly.