Your clients' data, on their terms — recorded.
You're asking clients to trust you with their vendors' documents, not just your own paperwork. So access is granted per client, in writing, by the client — and every grant is a record you can point at.
How a client grants you access
There's no switch inside your console that grants your agency access to a client. The client grants it, or it doesn't happen.
-
1
You request
You add the client and its primary contact. The company is created in a pending state and we email that contact a one-click authorization link. At this point your agency can see the client's name in your portfolio and nothing else — no vendors, no documents, no figures.
-
2
They grant
The contact opens the link, reads what they are authorizing, enters their email address, ticks the agreement and confirms. That single action is what unlocks the client for your team.
-
3
We record it
We stamp the granting email address, the timestamp, the originating IP address and the version of the agreement they saw, and write it into the client's own activity log. Both sides can see it.
Links expire
An authorization request is valid for 21 days. After that it expires and has to be re-sent, so a forwarded email from months ago can't quietly grant anything.
History is never rewritten
A granted authorization is never reopened or edited. Withdrawing closes it; asking again creates a new record. The trail of who agreed to which version, and when, stays intact.
Who can see what
| Role | Sees in the portfolio | Can work inside |
|---|---|---|
| Agency owner | Every client in the book, pending ones included | Every authorized client, with owner rights |
| Agency admin | Every client in the book, pending ones included | Every authorized client, with owner rights |
| Broker | Only the clients assigned to them | Only their assigned clients, once authorized |
Pending clients report nothing
A client who hasn't authorized you appears in your portfolio so you can chase them — with no contractor counts, no exception figures and no documents. There's nothing to accidentally read.
Withdrawal is immediate
When a client withdraws, they drop out of reach at once — not just hidden in the interface. The access check sits below the screens, so there's no view left that could render their data.
Working inside a client is not impersonation
When your team opens a client, they're still signed in as themselves. What they can see is decided by the consent that client granted, and their actions are logged under their own name.
How the data is handled
Encrypted in transit
Every connection to the application runs over TLS, and credentials are stored hashed, never in the clear.
Separated by company
Each client company is its own tenant. Which company a request may touch is re-checked on every single request against the consent on file, never carried over from a previous screen.
Built and hosted in the US
The application and its data sit in the United States.
A short, named list of processors
Documents are read by Google's Gemini API to extract coverage data; email is delivered by Resend; payment is handled by Stripe, which is also the only party that ever sees a card number. Each is named in the privacy policy.
Retention you can predict
Data is kept while the account is active, for up to 90 days after cancellation to allow reactivation, and may persist in encrypted backups for a further 30 days. Publicly sourced state license records are not tied to any account.
No advertising trackers
The only cookies are the ones that keep you signed in. We don't sell or trade personal information.
Uploads are constrained
Agency logos accept PNG, JPEG and WebP only. We don't take SVG, since it can carry script and serving one from our own origin isn't a risk worth taking for a logo.
Closing an account releases clients, it doesn't delete them
If your agency leaves, its client companies are detached from the portfolio with their vendors, documents and history intact. Their data was never yours to take with you.
The full detail lives in the privacy policy and the terms of service.
What we are not claiming
We don't hold a SOC 2 report or an ISO certification today, and we'd rather say so here than have you find out during a procurement review. What we do have is a small, well-defined system: consent recorded per client, tenancy enforced on every request, a named list of processors and an audit trail you can read. If your client's risk team needs something specific from us in writing, ask — we'd rather answer than dodge it.
Consent and access questions
Can we get into a client's data before they authorize us?
No. A pending client shows your team its name and nothing else. The check that grants access is part of the tenancy layer, not something the interface hides — there's no screen that renders an unauthorized client's data.
What happens when a client withdraws consent?
Their account leaves your reach immediately. Their data stays with them, untouched, and the withdrawal is written into the activity log alongside the original grant.
Can a broker on my team see accounts they are not working on?
Not unless you give them the reach. A broker sees only the clients assigned to them; owners and admins see the whole book. Changing someone's role is what widens or narrows that.
Who is recorded as having given consent?
The email address that actually submitted the authorization form, along with the timestamp, the IP address and the agreement version. If our support team ever records a consent on a client's behalf, the trail names our address rather than pretending the client clicked.
What if the agreement text changes?
It carries a version, and each granted authorization records the version the client saw. Old records keep naming their own version instead of being quietly upgraded.
Where does document extraction happen?
Uploaded certificates are sent to Google's Gemini API to read coverage types, limits and dates. It's named as a processor in the privacy policy, along with Stripe for payment and Resend for email.
Do you sell any of this data?
No. We don't sell, rent or trade personal information, and there are no advertising trackers in the product.
Read it, then try it against one account.
Add a single client, watch the consent step happen, and decide from there.
No credit card required. Questions? Email demo@trackmyvendor.com.