Security
Security at Agency Pilot
Your clients trust you with their ad accounts, their analytics and their customers' enquiries. This page explains exactly how we handle that — including every permission we ask Google and Meta for, and why.
No passwords, ever
Clients sign in on Google's, Meta's and each platform's own page. Guided steps always invite your agency's own login. We never ask for, store or see a password to a client's account.
Least privilege, per link
You choose the access level per platform when you create a link. Owner-level access is never offered, and a link only requests the permissions its platforms need.
No guessing
If a client's login reaches several properties, ad accounts or Pages, nothing is granted until someone picks the right one.
Encrypted tokens
Connection tokens are encrypted at rest with AES-256-GCM, sent to platforms in headers (never in URLs), and never exposed to the browser.
Agency isolation
Row-level security in the database keeps every agency's data separate. A client login can only ever reach that client's records.
Everything on the record
Every onboarding link logs opens, connections, grants and completions, and admins are notified when a link completes.
Two kinds of access, kept separate
When a client uses an onboarding link, two different things can happen, and it's worth being precise about them because most tools blur them together.
The access your agency receives. Your Google login added to the GA4 property, your business portfolio assigned as a partner on the Meta ad account, the invitation to Google Ads. That access is created inside each platform, belongs to your agency, and stays until the client removes it there — whether or not you keep using Agency Pilot.
The reporting connection Agency Pilot holds. A token that lets us read the numbers for the client's dashboard. It's encrypted at rest, scoped to the permissions on the consent screen, expires or refreshes according to each platform's rules, and ends the moment either side disconnects it — from Connected accounts in Agency Pilot, or from the client's Google or Facebook settings.
Transparency
Every permission we request, and why
A link only asks for the permissions its platforms need. Here is the complete list.
| Permission | Used for |
|---|---|
| openid, email, profile | Shows you and the client which Google login a connection belongs to. |
| analytics.readonly | Reads GA4 traffic, engagement and conversions for the client's dashboard and reports. |
| analytics.manage.users | Only on a link that asks for access: adds your agency's login to the chosen GA4 property at the role shown to the client. |
| webmasters.readonly | Reads Search Console performance for the client's site. Read-only. |
| business.manage | Reads Business Profile performance and, only on a link that asks for access, adds your login as Manager of the one account the client chooses. |
| tagmanager.readonly | Lists Tag Manager accounts and containers so the right one can be chosen. |
| tagmanager.manage.users | Only on a link that asks for access: adds your login with the container permission shown to the client. |
| adwords | Reads Google Ads performance and, only on a link that asks for access, sends one user invitation to your login. |
| datamanager | Only when you switch it on for a client: sends sold jobs to their Google Ads account as offline conversions. |
| content | Only on a link that asks for Merchant Center access: invites your login to the account the client chooses. Products and feeds are never read or changed. |
Meta (Facebook Login for Business)
| Permission | Used for |
|---|---|
| ads_read | Reads spend and delivery for the ad account the client shared. |
| ads_management | Manage links only: assigns your business portfolio as a partner on that ad account. Nothing else is written. |
| business_management | Manage links only: required by Meta to assign a partner on an asset owned by a business portfolio, and to detect your own Business ID. |
| pages_show_list | Lists the Pages the person manages so they can pick one. |
| pages_manage_metadata | Manage links only: assigns your business as a partner on a Page that isn't owned by a business portfolio. |
Every Meta API call is signed with an app secret proof. When a client removes Agency Pilot from their Facebook settings, Meta notifies us and the connection is marked revoked immediately; data-deletion requests get a status page the requester can check. Platform-by-platform detail is on each integration page.
Inside your workspace
- Roles. Owner, admin, member and viewer, with per-member permissions on top, enforced on the server for every request.
- Client logins. A client portal user can only reach their own business's records — never another client's, and never your internal notes, invoices to other clients or tasks.
- Two-factor sign-in. Authenticator-app 2FA for agency users, required before anything protected loads once it's on.
- Sign-in. Email and password or Sign in with Google, on short-lived signed session tokens.
- Credentials you give us. Telephony, CRM, mailbox and Conversions API credentials are stored encrypted, used only for the feature you connected them for, and deleted when you disconnect.
On your clients' websites
- Recording is off by default. Session recording is an add-on, switched on per client, with retention of 30, 60 or 90 days.
- Never recorded. Password and payment-card fields are always hidden, and pages that contain them aren't recorded at all. Typed text is hidden unless the client turns it on, with a second switch for sensitive fields.
- Consent. An optional consent banner can gate recording for everyone or visitors in chosen states, and honours Global Privacy Control.
- Retention. Raw visit data is kept 13 months, page snapshots 90 days, and recordings are deleted at expiry or 7 days after an agency's paid period ends.
- The fraud network. Signals shared across agencies to spot fraud use salted, one-way hashed identifiers. No agency can see another agency's visitors or leads.
Details for the people visiting your clients' sites are in the website visitor notice.
Infrastructure
Agency Pilot runs on managed cloud infrastructure in the United States, behind a content delivery and network security layer, with the database, authentication and file storage on a managed database platform. Traffic is encrypted in transit with TLS. Payments are handled by a PCI-compliant payment processor; we never see or store card numbers. The categories of providers are on the subprocessors page, and our commitments as a processor are in the Data Processing Addendum.
Server-side validation backs every check the interface makes; rate limits protect sign-in and public endpoints; webhooks are verified by signature; and errors are monitored so problems are fixed before they're reported.
Reporting a vulnerability
If you think you've found a security issue, email [email protected] with "Security report" in the subject. Please give us a reasonable chance to fix it before disclosing it, and don't access or change other people's data while testing. We'll acknowledge your report and keep you updated.
Security questions
- Is it safe to give a marketing agency access through Agency Pilot?
- Yes, and safer than the usual alternatives. Nobody shares a password; the client signs in on each platform's own page, sees the exact access being requested, and the agency receives the platform's own user or partner access, which the client can remove at any time.
- What happens to access if an agency stops using Agency Pilot?
- The access the agency received lives in Google, Meta and the other platforms and stays until the client removes it there. Agency Pilot's reporting connection is separate; it ends when either side disconnects it or the account is closed, and the stored tokens are deleted.
- Can one agency ever see another agency's data?
- No. Every table is protected by row-level security tied to the agency, and every request is checked on the server against the signed-in user's role.
- Where is data hosted?
- In the United States, with established cloud providers for the database, authentication, file storage and application hosting. The subprocessors page lists each category of provider, what it does and where; customers can request the named list.
- Do you have SOC 2?
- Not yet. We'd rather tell you that than imply it. If your procurement team needs a security questionnaire answered, email us and we'll complete it.
Access your clients can say yes to
Start a 14-day trial with 300 credits and send your first onboarding link today.
