Data security
Your reports are not a contact form.
What members send us — agency reports, proposals, contracts, exported account data — is commercially sensitive. It is handled accordingly, and the controls below are enforced in the product rather than promised in a policy.
We never collect advertising platform passwords
There is no field anywhere in this product for a Google, Meta or CRM password. If a member sends one, we ask them to change it immediately. Access, where it is granted at all, is read-only and granted through the platform’s own permission system.
Uploads are private by default
Files are stored in per-business private storage. There are no public URLs for member documents or reports — every download is served through a short-lived signed link issued only after an access check.
Per-business permissions
Every stored record carries a business identifier, and access rules are enforced at the database level rather than only in the application. A member cannot read another business’s data even if a bug in the interface tried to show it to them.
Administrator multi-factor authentication
Every AgencyGuard staff account with access to member data requires multi-factor authentication. Reviewer and administrator permissions are separated, and access is removed the day someone stops working on the account.
Report access is logged
Every time a member document or report is opened, the event is recorded with the account that opened it. If you ever want to know who has looked at your material, we can tell you.
Restricted uploads
Only PDF, image, CSV and Office document formats are accepted, with a 25 MB per-file limit. Executables and archives are rejected outright.
Consent before we review an account
We do not access anything you have not explicitly given us access to, and read-only access can be revoked by you at any time without contacting us.
A real deletion procedure
You can request deletion of your uploaded documents and account data at any time. We action it within 30 days and confirm in writing what was removed and what we are legally required to retain.
Read-only access
The safe way to give us visibility.
You never need to grant platform access to use AgencyGuard — uploading the report your agency already sends is enough for a useful review. If you do want deeper visibility, this is how it is done properly.
Google Ads
Add our email as a Read-only user at account level from Tools → Access and security. We can see performance, settings and change history. We cannot edit bids, budgets or campaigns.
Meta Business Manager
Assign us Analyst access to the ad account through Business Settings. We can see performance and creative. We cannot spend, publish or change anything.
Google Analytics 4
Grant Viewer access at property level. Enough to reconcile conversions; not enough to change your data collection.
Google Search Console
Add us as a Restricted user. We can read performance and indexing data without the ability to change site settings.
Every one of these can be revoked by you at any time, from inside the platform, without contacting us. That is the point of doing it this way.
Deletion
How to make us forget you.
Email hello@agencyguard.com.au from the address on your account and ask for deletion. We action it within 30 days and confirm in writing what was removed.
Uploaded documents and reports are deleted outright. Account and billing records are retained for seven years where Australian tax law requires it — we will tell you exactly what falls into that category rather than using it as a blanket excuse to keep everything.
If you simply cancel without requesting deletion, your reports stay downloadable for 30 days and uploaded documents are then removed automatically.
No access required
Start without giving us anything.
The free AgencyGuard Check asks eleven questions about your reporting. No documents, no account access, no card.