Identity & Access Management (IAM) • Google Cloud Platform
Holmegarth Security &
Central Authentication Platform
Holmegarth deploys a centralized, enterprise-grade Google Cloud & Firebase Authentication architecture. This provides frictionless Single Sign-On (SSO), hardware-grade token encryption, and strict role-based access control across all Holmegarth applications and client portals.
Google OAuth 2.0 Verified Architecture
Firebase Authentication & Identity Toolkit
TLS 1.3 / AES-256 Cloud KMS Encryption
UK GDPR & DPA 2018 Compliant
Centralized Single Sign-On (SSO)
Eliminates fragmented, insecure passwords across disparate internal tools. Users authenticate once through their verified corporate Google Workspace or Microsoft account to unlock authorized Holmegarth applications.
Google Cloud Security Backbone
Identity tokens are issued, signed, and verified via Google Cloud Platform's identity infrastructure. All authentication exchanges occur over TLS 1.3, with credentials encrypted at rest using Google Cloud Key Management Service (KMS).
Least-Privilege Tenant Isolation
Rigorous Role-Based Access Control (RBAC) ensures users only access data strictly provisioned to their enterprise account. Multi-tenant data segregation prevents cross-account exposure or unauthorized privilege escalation.
Connected Holmegarth Applications
When you sign in using your Google account, you will see Holmegarth or Holmegarth Identity on the authorization prompt. This single identity credential grants authenticated access to our full suite of enterprise software:
growth.holmegarth.com
The Growth Accelerator Platform
Enterprise Operating System: real-time financial baseline modeling, Power of 1 cash sensitivity, Whale Tail profit concentration, and 90-day Rock execution.
pulse.holmegarth.com
The Pulse Client Portal & CRM
Multi-tenant operational CRM tracking client touchpoints, retainer deliverables, time allocation audits, and automated commercial billing reconciliation.
riposte.holmegarth.com
Riposte Strategic Platform
Executive communication, secure file exchange, and orchestration engine managing high-velocity client deliverables and tactical escalations.
Enterprise Only
compositorai.app
Document Compositor SaaS
Automated boardroom presentation, PDF publishing, and report composition engine converting raw business metrics into executive-ready assets.
vopai.app
VOPai Executive Platform
Voice-operated executive workflows and automated drafting architecture converting verbal operational debriefs into structured business actions.
holmegarth.com
Compliance & Diagnostic Portals
Client diagnostic engines including the AI Maturity Snapshot, Cyber & IT Security Assessment, and Advanced Technical SEO checkers.
Scope Disclosures & Data Handling
In accordance with Google API Services User Data Policy, this section provides transparent disclosure on the exact OAuth scopes requested by Holmegarth when you sign in via Google.
| OAuth Scope | Classification | Operational Purpose | Data Retention |
|---|---|---|---|
| openid | Non-Sensitive | Verifies your identity cryptographically using OpenID Connect to confirm that the login attempt originated from a legitimate Google account. | Session duration |
| .../auth/userinfo.email | Non-Sensitive | Retrieves your verified corporate email address to associate your login with your organization's tenant workspace and assign role-based access rights. | Active subscription |
| .../auth/userinfo.profile | Non-Sensitive | Retrieves your full name and profile avatar image to personalize your application dashboard, meeting minutes, and accountable task assignments. | Active subscription |
Our Strict Data Protection Commitments
Zero Access to Gmail or Drive: Holmegarth does not request or possess access to your personal emails, files, Google Drive, or calendar data.
Zero Password Exposure: We never receive, handle, or store your Google password. Authentication occurs entirely within Google's isolated modal.
No Third-Party Monetization: We do not sell, rent, or share user profile or authentication data with external ad networks or commercial brokers.
Instant Self-Revocation: You can permanently disconnect Holmegarth's access at any time via your Google Account Permissions Manager.
UK GDPR & Data Protection Compliance
Holmegarth operates strictly in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. All user profile records, activity timestamps, and operational data are handled under legitimate commercial interest and contractual fulfillment principles.
Cryptographic & Network Controls
Our platform architecture utilizes industry-standard security controls engineered to protect high-growth enterprises and safeguard commercially sensitive data.
-
Short-Lived Tokens: Ephemeral OAuth JWT tokens with automated background refresh. -
Continuous Audit Logging: Google Cloud Operations logging for suspicious access attempts. -
Strict CORS & CSP: Tight Content Security Policies preventing clickjacking and cross-site scripting.
Questions Regarding Holmegarth Security?
For security assessments, enterprise vendor questionnaires, or specific authentication requests regarding your organization's Holmegarth deployment, contact our operational leadership directly.