Security & trust
We don't store your data. Here is what we do instead.
Attaché is an access layer, not a database. This page describes factually what passes through, what is kept, and how to cut everything off.
What passes through Attaché
- Read-only requests to the GA4, Google Ads, Search Console and Meta Ads APIs
- OAuth access tokens, encrypted at rest
- A log of executed requests (who, when, which platform) — auditable by the client
What Attaché never sees
- Passwords — sign-in happens at Google and Meta, never with us
- A copy of your data — nothing is stored, responses pass through in real time
- Your visitors' or end customers' personal data — only API aggregates pass through
Encrypted tokens, never shared
The only thing we keep: the OAuth tokens issued by Google and Meta. Encrypted at rest, transmitted over TLS only, never exposed to the agency or anyone else.
Hosting and GDPR compliance
Processing is GDPR-compliant. The infrastructure runs on Railway's US East region — which is beside the point here, because none of your account data ever rests there: requests are proxied in real time and nothing is written to disk. Only encrypted OAuth tokens are kept. Sub-processors are detailed in the privacy policy.
Read-only, minimal scope
The permissions requested from Google and Meta are read-only and limited to analytics and advertising data. Attaché cannot edit a campaign, publish, or administer an account.
One-click revocation — on both sides
The client can cut access at any time: all platforms are revoked at once. They can also do it directly at Google and Meta — Attaché is never a lock-in.
A security question?
We gladly answer your clients' security questionnaires and any technical question about how the connector works. [email protected]