Trust center
Security
Spilt Access Hub separates the public client experience from the staff administration service. Staff access is protected by Google Cloud Identity-Aware Proxy.
Request links
Each link contains a high-entropy token in the browser fragment, which is not sent in the initial HTTP request. Only a SHA-256 hash is retained. Links expire and can be replaced or revoked.
Provider credentials
Clients sign in on official provider pages. The application does not request provider passwords. The GA4, GTM, and Google Business Profile connectors use one-time OAuth state, PKCE, narrow service-specific scopes, a short-lived token encrypted with Cloud KMS, a 15-minute authorization session, and automatic cleanup. They do not request refresh tokens.
Verification
Client-reported completion remains pending until the agency confirms the exact asset and permission using authoritative provider readback.