Trust and security

Trust should be visible.

This page describes the controls Breeze uses today, the access customers retain, and the certifications or capabilities we do not claim.

Last updated: 17 August 2026

OAuth, not shared passwords

Authorized users connect supported accounts through the provider's consent flow.

Human-controlled actions

Breeze does not silently publish replies or change public business information.

Disconnect and delete

Customers can revoke provider access and request deletion of eligible personal data.

Current controls

What protects the product today.

Breeze is an early-stage business software product. The controls below are current design and operating boundaries, not a certification badge.

Connected accounts

  • Google Business Profile uses OAuth and never requires a customer's Google password.
  • Connections are limited to profiles the signed-in user is authorized to manage.
  • Tokens remain outside public application code.

Application and infrastructure

  • Website and application traffic use encrypted HTTPS connections.
  • Production secrets live in managed environment bindings rather than source code.
  • Production access is limited to people who need it to operate or support Breeze.
  • Operational logs support failure, abuse, and access investigations.

Product boundaries

  • Organization, brand, and location remain explicit access and data boundaries.
  • The current release does not claim automatic Google reply publishing or profile editing.
  • Future write actions require specific authorized customer action and an audit trail.

Customer control

  • Connected-platform access can be revoked through the provider.
  • Customers can ask Breeze to disconnect sources and delete eligible personal data.
  • Source coverage and refresh state should remain visible behind product summaries.

What we do not claim.

Breeze does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or another security certification unless and until the applicable audit or attestation is completed and published here.

Breeze is not owned, operated, endorsed, or certified by Google. Google Business Profile access and OAuth verification remain provider-controlled processes.

Report a vulnerability responsibly.

Email arun@breeze.io with the affected URL, steps to reproduce, and potential impact. Do not access, copy, or change data that is not yours.

We will acknowledge good-faith reports and investigate confirmed issues. For privacy and deletion requests, use the dedicated data-deletion process.