Built for your security review.
Enterprise-grade data handling, access controls, and documentation — ready to drop into your procurement process.
Encrypted in transit & at rest
All analytics connections use OAuth-scoped, read-only access over TLS. Credentials are never stored client-side.
Least-privilege access
Each client portal account sees only its own property data. No cross-client visibility, ever — enforced server-side.
GDPR & CCPA ready
Data processing agreements available, clear retention windows, and the right to export or delete on request.
No data resale
Your data is yours. We never share, sell, or train on client analytics. Period.
SOC 2 alignment
Our controls map to SOC 2 trust criteria — access, monitoring, and change management are documented and auditable.
Full audit trail
Every read of your analytics is logged. You can see exactly what was pulled, when, and by which system.
Questions procurement always asks.
Do you need write access to our Google Analytics?
No. We use a read-only analytics scope. We can’t and don’t modify your GA property, goals, or settings.
Can we use our own service account / SSO?
Yes. Enterprise clients can connect through their own Google Cloud service account, and we support SSO for portal access on enterprise plans.
How long is data retained?
Cached report data is retained for 24 months so you keep trend history without re-pulling. You can request deletion at any time.
Where is data stored?
On secured, encrypted infrastructure in the US (or EU on request). Data residency is configurable for enterprise engagements.
Need a DPA or security questionnaire?
We’ll send our standard data processing agreement and complete your security review packet within 48 hours.
Request security docs