GrowthAgents never touches client or matter data. We connect to your marketing surfaces — analytics, Search Console, your public website, your review and social profiles. We have no path to your case management system, your document store, your email, your trust accounting, or anything else covered by your duty of confidentiality.
That isn't a policy we promise to follow. It's the shape of the integration: we never request those credentials, so there is nothing to misuse and nothing to leak. Every connection below is listed with its permission level and a one-minute revocation path.
Nothing here is bundled. You can decline any single connection and the platform still runs — with less capability, which we'll tell you about before you start rather than after.
| Connection | Access | Why we need it | What it cannot do | How to revoke |
|---|---|---|---|---|
| Google Analytics 4 | Read only | To report which pages produced traffic and engagement, at the asset level. | Cannot edit your property, change configuration, delete data, or add users. | Remove onboarding@growthagents.ai under Admin → Property access management. Effective immediately. |
| Google Search Console | Read only | To report impressions, clicks and rankings per URL, and to see crawl or indexing errors. | Cannot submit removals, change settings, or verify new properties. | Remove the user under Settings → Users and permissions. Effective immediately. |
| WordPress | Publish | To publish finished content — checked against your jurisdiction's advertising rules — to your site without a human re-keying it. | Scoped to publishing content. CONFIRM: name the exact role and auth method. | Revoke the application password under Users → Profile. Effective immediately. |
| Google Business Profile | Manage | To read incoming reviews and post responses you have approved. | Cannot delete your listing, change your address or hours, or alter your NAP. | Remove our access under the profile's user list, or disconnect in your dashboard. |
| LinkedIn / social profiles | Post | To publish platform-specific social content on Growth and Scale plans. | Cannot read your direct messages, connections, or private profile data. | Revoke the app under the platform's connected-apps settings, or disconnect in your dashboard. |
// On read-only. Where a connection says read-only, that is the permission level Google enforces, not a promise we're making about our own behavior. You can verify it yourself in your own admin panel — which is the point. A commitment you can check beats a commitment you have to take on faith.
// On revocation. Every path above is one you control from your account, not a support ticket you file with us. If revoking access required emailing us, we would be the single point of failure in your own security posture. We're not willing to be that.
If a marketing vendor asks for any of the following, the correct answer is no — to us, and to everyone else.
This is the structural argument, and it is the only one worth making. Most vendor security pages describe controls protecting data the vendor shouldn't be holding in the first place. The stronger position is not holding it. We write marketing content about your practice areas and measure how the pages perform — that work does not require a single fact about a single client, so we never ask for one.
We're an AI company selling to a profession whose regulator has taken a specific position on AI tools. So this section is precise rather than reassuring.
Your practice areas, jurisdictions, published page content, public review text, and the research the agents gather about questions your prospective clients ask. All of it is either already public or supplied by you as marketing input.
Client names, matter facts, privileged communications, or anything from a system listed in the section above — because we never receive them in the first place.
CONFIRM before publishing. Intended text: Your content is not used to train any foundation model. We contract with our model providers under enterprise terms that prohibit training on customer inputs and outputs. Name the providers and link the relevant terms.
Every asset is checked against your jurisdiction's advertising rule set before it publishes. Anything that raises a flag stops and routes to a human with the reason attached.
// The obligation stays yours. Under ABA Formal Opinion 512, the duty of competence and confidentiality does not transfer to a vendor because a tool is involved. We can give you a system that never receives confidential information — we cannot give you a professional judgment. Every asset we publish is attributable to your firm, and reviewing what goes out under your name is your call to make, not ours to make for you.
// CONFIRM — this entire section is a template.
Every value below is a commitment you can be held to. It has not been filled in because guessing at production infrastructure would be worse than shipping nothing. Fill each blank against what is actually true in production, or delete the row.
The subprocessor list in particular is a legal disclosure, not marketing copy — an incomplete one is a liability in any DPA you later sign. Pull it from the actual vendor list, not from memory.
CONFIRM: name the cloud provider and region — e.g. "United States (AWS us-west-2)." If any subprocessor stores data outside the US, say which and where. Firms with international clients will ask.
CONFIRM: state transport encryption (TLS version) and encryption at rest, and only claim what is actually configured. "Encrypted in transit and at rest" is meaningless if a database is unencrypted.
CONFIRM: describe internal access controls — role-based access, who holds production credentials, whether access is logged. A small team is a fine answer; say the honest thing.
CONFIRM: how long performance data is retained while active, and how long after cancellation before deletion. Give a number of days, not "as long as necessary."
Third parties that process data on our behalf. CONFIRM and complete (blocks launch) — categories are prefilled, names are not.
| Category | Provider | What it processes | Location |
|---|---|---|---|
| Cloud hosting | CONFIRM | Application and database | CONFIRM |
| Database | CONFIRM | Account, content and performance data | CONFIRM |
| AI model providers | CONFIRM | Content generation and analysis inputs | CONFIRM |
| Transactional email | CONFIRM | Account and notification email | CONFIRM |
| Payments | CONFIRM | Billing — card data never reaches our servers | CONFIRM |
| Analytics | CONFIRM | Product usage on our own site and app | CONFIRM |
Every vendor security page is written to make a procurement checkbox go away. Here is what ours would fail on, stated before you find out.
// No SOC 2 report. CONFIRM. GrowthAgents is early-stage and has not completed a SOC 2 Type II audit. If a firm requires one from every vendor, this fails that requirement today. State the timeline if there is one, and say nothing if there isn't — a missed date is worse than no date.
// No ISO 27001, no HITRUST. CONFIRM. Same answer.
// No signed BAA. CONFIRM. GrowthAgents is not a HIPAA business associate and should not be treated as one. If a practice touches PHI, that data must not enter any marketing system, this one included.
// What we offer instead. A scope narrow enough that the certification question matters less than it would elsewhere. We hold read-only analytics access and publish rights to a public website. We do not hold your clients' information — so the worst realistic outcome of a breach on our side is exposure of your traffic statistics and your content calendar. That is a real cost, and it is not a confidentiality event.
If that trade is not one your firm can make, we would rather you decide that now than in month three. Email hello@growthagents.ai and ask the hardest version of your question — you'll get the actual answer, including when the answer is no.
Engaging a vendor doesn't move your ethical obligation onto the vendor. Three provisions are worth reading before you connect any marketing tool — not just this one.
Requires reasonable efforts to prevent inadvertent or unauthorized disclosure of, or access to, information relating to a representation. "Reasonable" is fact-specific — it scales with the sensitivity of the information and the risk involved.
Extends your responsibility to nonlawyer assistance, including outside vendors. You are expected to make reasonable efforts to ensure a vendor's conduct is compatible with your own professional obligations — which means asking the questions this page tries to answer.
The ABA's first formal guidance on generative AI in practice, issued July 2024. It holds that the duties of competence, confidentiality, client communication and reasonable fees apply directly to a lawyer's use of AI tools.
Model rules are a template. Your jurisdiction's version governs, and states differ meaningfully — which is the same reason the compliance check is configured per jurisdiction rather than against one national rulebook.
This page describes how our systems work. It isn't legal advice, and we're not your counsel. Your jurisdiction's rules govern, and the judgment about whether any vendor meets them is yours.
Report a suspected vulnerability or incident: security@growthagents.ai. CONFIRM this mailbox exists and is monitored. We don't run a paid bounty program, and we won't pursue good-faith researchers who report responsibly.
No. We connect to analytics, Search Console, your public website, and your review and social profiles. We never request access to your case management system, document store, email, intake system, or trust accounting, so there is no path from our platform to client or matter data. The full list of what we can and cannot reach is above.
Because attribution is the product. Without them we can tell you what we published but not what any of it did — which is the exact failure we built the company to fix. Both connections are read-only at the permission level Google enforces: we can read your traffic and ranking data, and we cannot change your configuration, delete data, or add users. Neither contains client information.
CONFIRM before publishing. Intended answer: No. We contract with model providers under terms that prohibit training on customer inputs and outputs.
CONFIRM. Intended answer: No, not today — we're early and haven't completed a Type II audit. What we offer instead is a narrow scope: read-only analytics access and publish rights to a public website, and no client data at all. If a firm requires SOC 2 from every vendor, we'll fail that requirement, and we'd rather tell you now.
Content published to your WordPress stays on your WordPress — we don't remove or claw back published work, on any plan. Our copy of your account and performance data is deleted on request at no charge, and we confirm in writing when it's done. CONFIRM the deletion window.
Yes, and you should be able to — a vendor who has to approve their own removal is a single point of failure in your security posture. Every connection is revocable from your own admin panel: Google Analytics under Property access management, Search Console under Users and permissions, WordPress by revoking the application password, social platforms under connected apps. All take effect immediately.
CONFIRM. Intended answer: Yes. Email hello@growthagents.ai and we'll turn a standard DPA around within a few business days. Questionnaires get answered honestly, including where the answer is "we don't do that yet." If we cannot commit to this, say so instead — a promise missed during procurement costs more than a no.
Yes. We are not a HIPAA business associate and do not sign BAAs, so protected health information must not enter our platform — the same as it must not enter any marketing system. In practice this rarely constrains the work, because marketing content describes your practice areas rather than any individual's case. If your workflow would require PHI to reach a marketing tool, that workflow needs changing regardless of which vendor you pick.
The free SiteScan reads your public pages the same way an answer engine does. No analytics connection, no credentials, no card. If you like the report, the access questions come after — and you'll have already read the answers.