Skip to content

Trust & security

You stay in control of everything that touches your business.

gx360 is built around one rule: agents and experts can prepare the work, but nothing that touches your live site or accounts happens without your approval.

The access model

How a change actually reaches your site.

Every change follows the same path — prepared by an agent, approved by you, carried out by the agent, and logged.

01

Agents watch & propose

AI agents monitor your connected sources, surface findings and prepare draft fixes.

02

You approve

Anything that touches your live site or accounts waits for your yes. We ask by email, WhatsApp or a call, and record who approved, how and when.

03

gx360 carries it out

The agents make the approved change on the connected account and log it — or hand your developer an exact brief. Nothing goes out unapproved, ever.

04

Every change is logged

What changed, when, why and who approved it stays in an audit trail.

Your Google data stays in your Google account

We read through Google’s API with the access you grant. We don’t copy your accounts out, and you can revoke access any time.

AI assistant access is read-only

The optional MCP connector reads your data only — it cannot change anything, and nothing is connected until you do it.

No public change without approval

Agents and specialists can prepare anything, but nothing public ships until you approve it.

Data handling

What each connector shares, and for how long.

You grant access connector by connector. Here is what gx360 reads, where it lives and how long we keep it.

ConnectorWhat gx360 accessesWhere it’s storedRetention
Google Search ConsoleRead-only: search queries, impressions, clicks and index coverage.Stays in your Google account; read via Google’s API.Report snapshots kept for the engagement; removed on request.
Google Analytics (GA4)Read-only: traffic, conversions and channel performance.Stays in your Google account; read via Google’s API.Report snapshots kept for the engagement; removed on request.
Google AdsRead, plus the changes you approve: search terms, keywords, conversion goals.Stays in your Google account; approved changes applied by an admin on your team.Change log retained; account data is not copied out.
Website / CMSPublic pages we crawl; CMS edit access only when publishing is in scope.Crawled content stored with your gx360 workspace.Kept for the engagement; removed on request.
CRM / pipeline (optional)Read-only deal and lead stages, only when pipeline tracking is agreed.Aggregated into your workspace reports.Kept for the engagement; removed on request.
AI model providersOnly the text needed for a specific task, e.g. an audit prompt or a draft.Processed by the provider to return a result; not used to train their models.Not retained for training; transient processing only.

Model providers

Which AI sees your data.

gx360 uses large language models to draft and analyse. Today that means OpenAI and DeepSeek, chosen per task for quality and cost. Only the text needed for a task is sent, and your data is not used to train any provider’s models.

Customers with stricter requirements can request an OpenAI-only configuration, so no task is routed to any other provider. When you connect Claude, it reads your gx360 data — read-only — under your Anthropic account.

OpenAIDeepSeekOpenAI-only option

Start with the evidence

Questions about access or data residency?

Start the free trial with read-only access, or talk to sales and we’ll walk through exactly what gx360 can and can’t touch.

Want IOSS experts to do the work? Talk to sales

Start free trial ↗