Security and control
A system that manages has to be the first to accept limits.
This is exactly who decides, what runs on its own — nothing — and where each piece of data lives.
Three non-negotiable rules.
Nothing sensitive is executed without a person’s sign-off. Each company’s data is kept isolated from the others’. Every decision keeps its trail: where it came from, what information it used and what consequences it had. These aren’t settings that can be switched off to go faster: they are how the system is built.
What exactly happens before anything is executed.
A BGS decision goes through three states. Only you move the middle one.
- State 1Prepared
BGS has gathered the information, brought in the specialists and drafted the proposal with its rationale and its alternative. It hasn’t touched anything yet.
- State 2Awaiting your sign-off
The decision stays on your desk. You can sign off on it, hold it or send it back to be redone. If you do nothing, nothing happens: the system doesn’t read silence as a yes.
- State 3Executed or held
It is executed only after your sign-off, and a record is kept of who signed, when and on what information. If you hold it, that is recorded too.
Advertising connections are also read-only by design: BGS analyzes and proposes on those accounts, and execution always goes through you.
Where everything lives and who can see it.
Company-level data isolation
Permission is granted per person–company pair. If you run three companies, each one has its own space and its own authorization: there is no view that mixes them by accident.
Explicit authorization
BGS doesn’t access any tool until someone with permission connects it. Authorization is granted on each provider’s official screen; BGS neither sees nor stores your passwords.
Traceability
Every decision keeps the data that originated it, the rationale, the sources and the expected consequences. A decision with no trail is a decision you shouldn’t sign off on.
Contained cost
Operating cost is visible at all times. A system that works on its own overnight has to be able to tell you how much it spent doing so.
Engine Room
A control panel always answers the uncomfortable question: can I trust BGS today? What has been done, what is awaiting a decision and what has failed.
Legal basis
The processing of your data and the processors involved are detailed in the Privacy Policy, with no generic cross-references.
What BGS doesn’t do, stated plainly.
A system that claims it can do everything isn’t trustworthy. These limits are real and verifiable.
Five things that don’t happen
- It doesn’t execute changes in your advertising accounts. Advertising connectors are read-only by design. It analyzes and proposes; you execute.
- It doesn’t access anything without authorization. Not a tool, not an email, not a document. The connection is opened by a person with permission.
- It doesn’t conclude without enough information. If it lacks context, it says so, instead of filling the gap with a well-written assumption.
- It doesn’t mix one company’s data with another’s, even if they share management or owner.
- It doesn’t read silence as approval. A decision that hasn’t been signed off stays unexecuted for as long as it takes.
Where each connection stands today.
Because “it integrates with everything” is exactly the kind of phrase you shouldn’t believe.
- Operational Platform access and per-company isolation Access control and data separation between companies are implemented in the system and are the foundation everything else rests on.
- In development Amazon · Google · Meta · Microsoft 365 · LinkedIn · Stripe · banking · email Connector built and registered; each platform’s official access process still needs to be completed, and that process is underway.
- Vision Shopify · ERP and CRM · WhatsApp Business Planned in the system design. They don’t have a connector built yet.
Questions we often get.
Can BGS do anything without my approval?
Not if it is a sensitive action. BGS gathers information, analyzes and prepares decisions on its own, but executing any action with consequences goes through a person’s sign-off. A decision that hasn’t been signed off stays unexecuted; the system doesn’t read silence as approval.
What happens to the data if I run several companies?
It stays isolated. Permission is granted per person–company pair, so each company has its own space and its own authorization. One company’s data doesn’t mix with another’s, even if they share management or owner.
Does BGS see my passwords?
No. Connections are authorized on each provider’s official consent screen, using standard authorization mechanisms. BGS neither sees nor manages the credentials for those accounts. The details are in the Privacy Policy.
Can BGS change my advertising campaigns?
Not today, and not for lack of development: advertising connectors are read-only by design. BGS analyzes performance and proposes concrete changes, and execution always goes through your approval on the corresponding platform.
Want to see it with your own data?
In the assessment we review what you would connect, what BGS would see and which decisions you’d have to sign off on. No commitment, and nothing gets connected at this stage.
30 minutes · we start from your company, not a script · limited spots during the pilot phase.