Security & Compliance

Built for your security review.

Enterprise-grade data handling, access controls, and documentation — ready to drop into your procurement process.

Encrypted in transit & at rest

All analytics connections use OAuth-scoped, read-only access over TLS. Credentials are never stored client-side.

Least-privilege access

Each client portal account sees only its own property data. No cross-client visibility, ever — enforced server-side.

GDPR & CCPA ready

Data processing agreements available, clear retention windows, and the right to export or delete on request.

No data resale

Your data is yours. We never share, sell, or train on client analytics. Period.

SOC 2 alignment

Our controls map to SOC 2 trust criteria — access, monitoring, and change management are documented and auditable.

Full audit trail

Every read of your analytics is logged. You can see exactly what was pulled, when, and by which system.

Questions procurement always asks.

Do you need write access to our Google Analytics?

No. We use a read-only analytics scope. We can’t and don’t modify your GA property, goals, or settings.

Can we use our own service account / SSO?

Yes. Enterprise clients can connect through their own Google Cloud service account, and we support SSO for portal access on enterprise plans.

How long is data retained?

Cached report data is retained for 24 months so you keep trend history without re-pulling. You can request deletion at any time.

Where is data stored?

On secured, encrypted infrastructure in the US (or EU on request). Data residency is configurable for enterprise engagements.

Need a DPA or security questionnaire?

We’ll send our standard data processing agreement and complete your security review packet within 48 hours.

Request security docs
Get my free SEO score
60-second audit · see your extinction risk & fixes
Start audit