Holmegarth Security





Identity & Access Management (IAM) • Google Cloud Platform

Holmegarth Security &
Central Authentication Platform

Holmegarth deploys a centralized, enterprise-grade Google Cloud & Firebase Authentication architecture. This provides frictionless Single Sign-On (SSO), hardware-grade token encryption, and strict role-based access control across all Holmegarth applications and client portals.



Google OAuth 2.0 Verified Architecture



Firebase Authentication & Identity Toolkit



TLS 1.3 / AES-256 Cloud KMS Encryption



UK GDPR & DPA 2018 Compliant
01

Centralized Single Sign-On (SSO)

Eliminates fragmented, insecure passwords across disparate internal tools. Users authenticate once through their verified corporate Google Workspace or Microsoft account to unlock authorized Holmegarth applications.

Standard: OpenID Connect & OAuth 2.0
02

Google Cloud Security Backbone

Identity tokens are issued, signed, and verified via Google Cloud Platform's identity infrastructure. All authentication exchanges occur over TLS 1.3, with credentials encrypted at rest using Google Cloud Key Management Service (KMS).

Encryption: 256-Bit AES & RSA Cryptographic Signatures
03

Least-Privilege Tenant Isolation

Rigorous Role-Based Access Control (RBAC) ensures users only access data strictly provisioned to their enterprise account. Multi-tenant data segregation prevents cross-account exposure or unauthorized privilege escalation.

Governance: Strict Workspace Scoping & Audit Logs
Unified Security Architecture

Connected Holmegarth Applications

When you sign in using your Google account, you will see Holmegarth or Holmegarth Identity on the authorization prompt. This single identity credential grants authenticated access to our full suite of enterprise software:

Executive BOS
growth.holmegarth.com

The Growth Accelerator Platform

Enterprise Operating System: real-time financial baseline modeling, Power of 1 cash sensitivity, Whale Tail profit concentration, and 90-day Rock execution.

Auth: Google SSO • RBAC
Explore →
Commercial CRM
pulse.holmegarth.com

The Pulse Client Portal & CRM

Multi-tenant operational CRM tracking client touchpoints, retainer deliverables, time allocation audits, and automated commercial billing reconciliation.

Auth: Google SSO • RBAC
Explore →
Workflow Node
riposte.holmegarth.com

Riposte Strategic Platform

Executive communication, secure file exchange, and orchestration engine managing high-velocity client deliverables and tactical escalations.

Auth: Google SSO • Token Auth
Enterprise Only
Document SaaS
compositorai.app

Document Compositor SaaS

Automated boardroom presentation, PDF publishing, and report composition engine converting raw business metrics into executive-ready assets.

Auth: Google SSO • JWT
Open App →
AI Engine
vopai.app

VOPai Executive Platform

Voice-operated executive workflows and automated drafting architecture converting verbal operational debriefs into structured business actions.

Auth: Google SSO • OAuth 2.0
Open App →
Governance
holmegarth.com

Compliance & Diagnostic Portals

Client diagnostic engines including the AI Maturity Snapshot, Cyber & IT Security Assessment, and Advanced Technical SEO checkers.

Auth: Google SSO • Public
Methodology →
Google OAuth 2.0 Compliance

Scope Disclosures & Data Handling

In accordance with Google API Services User Data Policy, this section provides transparent disclosure on the exact OAuth scopes requested by Holmegarth when you sign in via Google.

OAuth ScopeClassificationOperational PurposeData Retention
openidNon-SensitiveVerifies your identity cryptographically using OpenID Connect to confirm that the login attempt originated from a legitimate Google account.Session duration
.../auth/userinfo.emailNon-SensitiveRetrieves your verified corporate email address to associate your login with your organization's tenant workspace and assign role-based access rights.Active subscription
.../auth/userinfo.profileNon-SensitiveRetrieves your full name and profile avatar image to personalize your application dashboard, meeting minutes, and accountable task assignments.Active subscription


Our Strict Data Protection Commitments

✓
Zero Access to Gmail or Drive: Holmegarth does not request or possess access to your personal emails, files, Google Drive, or calendar data.
✓
Zero Password Exposure: We never receive, handle, or store your Google password. Authentication occurs entirely within Google's isolated modal.
✓
No Third-Party Monetization: We do not sell, rent, or share user profile or authentication data with external ad networks or commercial brokers.
✓
Instant Self-Revocation: You can permanently disconnect Holmegarth's access at any time via your Google Account Permissions Manager.
GOVERNANCE & LEGAL

UK GDPR & Data Protection Compliance

Holmegarth operates strictly in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. All user profile records, activity timestamps, and operational data are handled under legitimate commercial interest and contractual fulfillment principles.

Data Controller: Holmegarth Business Support
Controller Email: support@holmegarth.com
Data Residency: Google Cloud Platform (europe-west2 / London & Tier 3 EU datacentres)
SECURITY PROTOCOLS

Cryptographic & Network Controls

Our platform architecture utilizes industry-standard security controls engineered to protect high-growth enterprises and safeguard commercially sensitive data.


  • Short-Lived Tokens: Ephemeral OAuth JWT tokens with automated background refresh.

  • Continuous Audit Logging: Google Cloud Operations logging for suspicious access attempts.

  • Strict CORS & CSP: Tight Content Security Policies preventing clickjacking and cross-site scripting.

Questions Regarding Holmegarth Security?

For security assessments, enterprise vendor questionnaires, or specific authentication requests regarding your organization's Holmegarth deployment, contact our operational leadership directly.