Law firms Citation Share Compare Pricing Blog About Sign in Start free site scan
Home/Security & data
Security & data handling

What we can reach, what we can't, and how to cut it off

GrowthAgents never touches client or matter data. We connect to your marketing surfaces — analytics, Search Console, your public website, your review and social profiles. We have no path to your case management system, your document store, your email, your trust accounting, or anything else covered by your duty of confidentiality.

That isn't a policy we promise to follow. It's the shape of the integration: we never request those credentials, so there is nothing to misuse and nothing to leak. Every connection below is listed with its permission level and a one-minute revocation path.

Last reviewed: August 2026 · Questions: hello@growthagents.ai
Client matter data
Never requested, never stored
Analytics access
Read-only, revocable by you
Used to train AI models
No — see AI processing below
On cancellation
Deleted on request, no fee
Every connection, in full

What we ask for, and what each one can actually do

Nothing here is bundled. You can decline any single connection and the platform still runs — with less capability, which we'll tell you about before you start rather than after.

Connection Access Why we need it What it cannot do How to revoke
Google Analytics 4 Read only To report which pages produced traffic and engagement, at the asset level. Cannot edit your property, change configuration, delete data, or add users. Remove onboarding@growthagents.ai under Admin → Property access management. Effective immediately.
Google Search Console Read only To report impressions, clicks and rankings per URL, and to see crawl or indexing errors. Cannot submit removals, change settings, or verify new properties. Remove the user under Settings → Users and permissions. Effective immediately.
WordPress Publish To publish finished content — checked against your jurisdiction's advertising rules — to your site without a human re-keying it. Scoped to publishing content. CONFIRM: name the exact role and auth method. Revoke the application password under Users → Profile. Effective immediately.
Google Business Profile Manage To read incoming reviews and post responses you have approved. Cannot delete your listing, change your address or hours, or alter your NAP. Remove our access under the profile's user list, or disconnect in your dashboard.
LinkedIn / social profiles Post To publish platform-specific social content on Growth and Scale plans. Cannot read your direct messages, connections, or private profile data. Revoke the app under the platform's connected-apps settings, or disconnect in your dashboard.

// On read-only. Where a connection says read-only, that is the permission level Google enforces, not a promise we're making about our own behavior. You can verify it yourself in your own admin panel — which is the point. A commitment you can check beats a commitment you have to take on faith.

// On revocation. Every path above is one you control from your account, not a support ticket you file with us. If revoking access required emailing us, we would be the single point of failure in your own security posture. We're not willing to be that.

The part that matters most

What we never ask for, and could not access if we wanted to

If a marketing vendor asks for any of the following, the correct answer is no — to us, and to everyone else.

GrowthAgents has no access to:

  • Your case or matter management system
  • Client files, documents, or your DMS
  • Firm or attorney email accounts
  • Client names, contact details, or matter facts
  • Trust accounting or any financial system
  • Billing records or time entries
  • Intake forms or intake system contents
  • Calendars, dockets, or court deadlines
  • Privileged communications of any kind
  • Anything covered by your duty of confidentiality

This is the structural argument, and it is the only one worth making. Most vendor security pages describe controls protecting data the vendor shouldn't be holding in the first place. The stronger position is not holding it. We write marketing content about your practice areas and measure how the pages perform — that work does not require a single fact about a single client, so we never ask for one.

AI processing

What the models see, and what they keep

We're an AI company selling to a profession whose regulator has taken a specific position on AI tools. So this section is precise rather than reassuring.

What goes to a model

Your practice areas, jurisdictions, published page content, public review text, and the research the agents gather about questions your prospective clients ask. All of it is either already public or supplied by you as marketing input.

What never goes to a model

Client names, matter facts, privileged communications, or anything from a system listed in the section above — because we never receive them in the first place.

Training

CONFIRM before publishing. Intended text: Your content is not used to train any foundation model. We contract with our model providers under enterprise terms that prohibit training on customer inputs and outputs. Name the providers and link the relevant terms.

Human review

Every asset is checked against your jurisdiction's advertising rule set before it publishes. Anything that raises a flag stops and routes to a human with the reason attached.

// The obligation stays yours. Under ABA Formal Opinion 512, the duty of competence and confidentiality does not transfer to a vendor because a tool is involved. We can give you a system that never receives confidential information — we cannot give you a professional judgment. Every asset we publish is attributable to your firm, and reviewing what goes out under your name is your call to make, not ours to make for you.

Storage, retention, deletion

Where it lives and how long it stays

// CONFIRM — this entire section is a template.

Every value below is a commitment you can be held to. It has not been filled in because guessing at production infrastructure would be worse than shipping nothing. Fill each blank against what is actually true in production, or delete the row.

The subprocessor list in particular is a legal disclosure, not marketing copy — an incomplete one is a liability in any DPA you later sign. Pull it from the actual vendor list, not from memory.

Where data is stored

CONFIRM: name the cloud provider and region — e.g. "United States (AWS us-west-2)." If any subprocessor stores data outside the US, say which and where. Firms with international clients will ask.

Encryption

CONFIRM: state transport encryption (TLS version) and encryption at rest, and only claim what is actually configured. "Encrypted in transit and at rest" is meaningless if a database is unencrypted.

Who on our side can see it

CONFIRM: describe internal access controls — role-based access, who holds production credentials, whether access is logged. A small team is a fine answer; say the honest thing.

Retention

CONFIRM: how long performance data is retained while active, and how long after cancellation before deletion. Give a number of days, not "as long as necessary."

Subprocessors

Third parties that process data on our behalf. CONFIRM and complete (blocks launch) — categories are prefilled, names are not.

Category Provider What it processes Location
Cloud hostingCONFIRMApplication and databaseCONFIRM
DatabaseCONFIRMAccount, content and performance dataCONFIRM
AI model providersCONFIRMContent generation and analysis inputsCONFIRM
Transactional emailCONFIRMAccount and notification emailCONFIRM
PaymentsCONFIRMBilling — card data never reaches our serversCONFIRM
AnalyticsCONFIRMProduct usage on our own site and appCONFIRM

Deleting your data

  1. Cancel, or just ask. Email hello@growthagents.ai from the address on the account. You don't have to cancel to request deletion of a specific dataset.
  2. We confirm what will be deleted, in writing, before anything is removed — so there's a record on both sides.
  3. Deletion completes within CONFIRM days, including backups, and we confirm in writing when it's done. No fee, at any plan level.
  4. Content published to your site stays yours. We don't remove or claw back anything already published to your WordPress. Deleting our copy of the data doesn't touch your pages.
Say the uncomfortable thing first

What we don't have, and won't pretend to

Every vendor security page is written to make a procurement checkbox go away. Here is what ours would fail on, stated before you find out.

// No SOC 2 report. CONFIRM. GrowthAgents is early-stage and has not completed a SOC 2 Type II audit. If a firm requires one from every vendor, this fails that requirement today. State the timeline if there is one, and say nothing if there isn't — a missed date is worse than no date.

// No ISO 27001, no HITRUST. CONFIRM. Same answer.

// No signed BAA. CONFIRM. GrowthAgents is not a HIPAA business associate and should not be treated as one. If a practice touches PHI, that data must not enter any marketing system, this one included.

// What we offer instead. A scope narrow enough that the certification question matters less than it would elsewhere. We hold read-only analytics access and publish rights to a public website. We do not hold your clients' information — so the worst realistic outcome of a breach on our side is exposure of your traffic statistics and your content calendar. That is a real cost, and it is not a confidentiality event.

If that trade is not one your firm can make, we would rather you decide that now than in month three. Email hello@growthagents.ai and ask the hardest version of your question — you'll get the actual answer, including when the answer is no.

Your side of it

The duty stays with you. Here's the rule

Engaging a vendor doesn't move your ethical obligation onto the vendor. Three provisions are worth reading before you connect any marketing tool — not just this one.

Model Rule 1.6(c)

Requires reasonable efforts to prevent inadvertent or unauthorized disclosure of, or access to, information relating to a representation. "Reasonable" is fact-specific — it scales with the sensitivity of the information and the risk involved.

Read Rule 1.6 →

Model Rule 5.3

Extends your responsibility to nonlawyer assistance, including outside vendors. You are expected to make reasonable efforts to ensure a vendor's conduct is compatible with your own professional obligations — which means asking the questions this page tries to answer.

ABA Formal Opinion 512

The ABA's first formal guidance on generative AI in practice, issued July 2024. It holds that the duties of competence, confidentiality, client communication and reasonable fees apply directly to a lawyer's use of AI tools.

Read the ABA's summary →

Your state's rule, not the model rule

Model rules are a template. Your jurisdiction's version governs, and states differ meaningfully — which is the same reason the compliance check is configured per jurisdiction rather than against one national rulebook.

How the compliance check works →

This page describes how our systems work. It isn't legal advice, and we're not your counsel. Your jurisdiction's rules govern, and the judgment about whether any vendor meets them is yours.

If something goes wrong

What happens in an incident

  1. We tell you within CONFIRM hours of confirming an incident affects your account — by email to every user on the account, not a status page you'd have to be watching.
  2. We tell you what we know and what we don't. Including when the honest answer is "we're still determining scope." A partial disclosure on day one beats a complete one on day ten, because your notification obligations may start before ours are finished.
  3. We name what was accessed, specifically enough for you to assess your own obligations. "Some customer data may have been affected" is not an answer.
  4. We publish a written postmortem covering cause, scope and what changed as a result.

Report a suspected vulnerability or incident: security@growthagents.ai. CONFIRM this mailbox exists and is monitored. We don't run a paid bounty program, and we won't pursue good-faith researchers who report responsibly.

Straight answers

What firms ask before they connect anything

Can GrowthAgents see my clients' information?+

No. We connect to analytics, Search Console, your public website, and your review and social profiles. We never request access to your case management system, document store, email, intake system, or trust accounting, so there is no path from our platform to client or matter data. The full list of what we can and cannot reach is above.

Why do you need my Google Analytics and Search Console?+

Because attribution is the product. Without them we can tell you what we published but not what any of it did — which is the exact failure we built the company to fix. Both connections are read-only at the permission level Google enforces: we can read your traffic and ranking data, and we cannot change your configuration, delete data, or add users. Neither contains client information.

Is my content used to train AI models?+

CONFIRM before publishing. Intended answer: No. We contract with model providers under terms that prohibit training on customer inputs and outputs.

Are you SOC 2 certified?+

CONFIRM. Intended answer: No, not today — we're early and haven't completed a Type II audit. What we offer instead is a narrow scope: read-only analytics access and publish rights to a public website, and no client data at all. If a firm requires SOC 2 from every vendor, we'll fail that requirement, and we'd rather tell you now.

What happens to my data if I cancel?+

Content published to your WordPress stays on your WordPress — we don't remove or claw back published work, on any plan. Our copy of your account and performance data is deleted on request at no charge, and we confirm in writing when it's done. CONFIRM the deletion window.

Can I revoke access without contacting you?+

Yes, and you should be able to — a vendor who has to approve their own removal is a single point of failure in your security posture. Every connection is revocable from your own admin panel: Google Analytics under Property access management, Search Console under Users and permissions, WordPress by revoking the application password, social platforms under connected apps. All take effect immediately.

Will you sign a DPA or a vendor security questionnaire?+

CONFIRM. Intended answer: Yes. Email hello@growthagents.ai and we'll turn a standard DPA around within a few business days. Questionnaires get answered honestly, including where the answer is "we don't do that yet." If we cannot commit to this, say so instead — a promise missed during procurement costs more than a no.

My practice touches health information. Does that change anything?+

Yes. We are not a HIPAA business associate and do not sign BAAs, so protected health information must not enter our platform — the same as it must not enter any marketing system. In practice this rarely constrains the work, because marketing content describes your practice areas rather than any individual's case. If your workflow would require PHI to reach a marketing tool, that workflow needs changing regardless of which vendor you pick.

Nothing to connect yet

The scan doesn't need access to anything

The free SiteScan reads your public pages the same way an answer engine does. No analytics connection, no credentials, no card. If you like the report, the access questions come after — and you'll have already read the answers.