Surevisible
Security

Access that cannot change anything

Surevisible asks Google for read-only scopes. It is not capable of modifying a property, a setting or a campaign, not by policy, by permission.

The problem

Granting a third party access to your analytics usually means granting more than it needs, and trusting a policy document that it will not use the rest.

What we mean

The scopes requested are webmasters.readonly and analytics.readonly. There is no write permission to misuse, so the guarantee does not depend on our restraint. Revoking access in your Google account revokes it here at the same moment.

2

scopes requested, both of them read-only

How it works

Start to answer

  1. 01

    You authorise

    One Google consent screen, listing exactly the two read scopes.

  2. 02

    Tokens are encrypted

    Refresh tokens are encrypted at rest with a key that never leaves your install.

  3. 03

    Reads only

    Every call the connectors make is a read. There is no code path that writes to Google.

  4. 04

    You can revoke

    From your Google account, at any time, without asking us.

Before and after

What actually changes

The security review

Before

A questionnaire about what the vendor could theoretically do with write access.

After

The scopes are read-only. The question does not arise.

Offboarding a client

Before

Chasing a vendor to confirm they deleted their access.

After

Revoke in Google. Access ends immediately.

Least privilege, actually

Two scopes, both read.

  • webmasters.readonly
  • analytics.readonly
  • No write scope requested or held

Credentials at rest

Nothing sensitive is stored in the clear.

  • Refresh tokens encrypted with a local master key
  • Never rendered in the UI or the admin console
  • Never logged

Your data stays yours

It is used to answer your questions and nothing else.

  • Not used to train models
  • Not shared between workspaces
  • Deleted with the brand or the workspace

Why the admin console shows no tokens

An internal console that prints credentials is a credential leak with a login page in front of it. The operator view shows a connection's status and its last error and nothing else: enough to fix it, never enough to impersonate it.

In short

The blast radius of a Surevisible compromise is read access to data you can already export yourself.

See the whole brand

Search, analytics, ads, revenue, CRM and support, pulled into one view per brand and kept current. Connect the first source in a few minutes.