Trust center

Security

Spilt Access Hub separates the public client experience from the staff administration service. Staff access is protected by Google Cloud Identity-Aware Proxy.

Request links

Each link contains a high-entropy token in the browser fragment, which is not sent in the initial HTTP request. Only a SHA-256 hash is retained. Links expire and can be replaced or revoked.

Provider credentials

Clients sign in on official provider pages. The application does not request provider passwords. The GA4, GTM, and Google Business Profile connectors use one-time OAuth state, PKCE, narrow service-specific scopes, a short-lived token encrypted with Cloud KMS, a 15-minute authorization session, and automatic cleanup. They do not request refresh tokens.

Verification

Client-reported completion remains pending until the agency confirms the exact asset and permission using authoritative provider readback.