TRUST & SECURITY

How we handle your practice's — and your clients' — data.

You protect sensitive financial information for a living, so we will not insult you with vague reassurances. This page states the operating posture, the boundaries we keep, what is verified today, and what we refuse to claim without evidence.

THE SHORT VERSION

PII-aware by design, configured per practice, human-controlled where it counts.

Your data stays yours. AI works inside an approved front-office scope. Sensitive matters move to a person.

YOUR DATA

Your practice's data belongs to your practice.

01

Configured for the practice

The implementation, data paths, users, and handoffs are documented for the actual client. We do not publish a stronger isolation claim until its platform configuration is verified.

02

Encrypted in transit

The public site uses HTTPS. Connected vendor traffic is expected to use authenticated encrypted transport according to each integration.

03

Your assets stay yours

Your website, brand assets, content, and client relationships remain yours. Handoff responsibilities are documented in the engagement.

04

Used for the agreed system

Practice data is used to operate the website, assistants, CRM, and approved workflows—not sold, rented, or repurposed as a shared marketing list.

HOW WE USE AI

AI does the repetitive front-office work. People keep the judgment.

Assistants support approved new-prospect intake, scheduling, reviews, follow-up, and admin. They do not handle sensitive client matters under the default scope.

AI MAY HANDLEApproved prospect questions, capture, booking, reminders, and defined follow-up.
ROUTE TO A PERSONSensitive, account-specific, professional, ambiguous, or exception matters.
CHANGE CONTROLThe practice approves what assistants can say and do before the workflow changes.
WHO CAN SEE WHAT

Access must be explicit, attributable, and reviewable.

Roles and permissions depend on the platforms and the client configuration. We document who needs access, what they need it for, and where authentication lives rather than making a universal least-privilege claim without evidence.

Cloudflare Trust Hub External verification →GoHighLevel Trust Center External verification →
Certification status

No certification badges are displayed without verification. PGT does not claim SOC 2, ISO 27001, HIPAA, PCI, or similar certification on this page.

CALLS, TEXTS & OUTREACH

Build the guardrails before the campaign.

Automated calls and texts are regulated. The workflow should use approved sender identity, consent and suppression rules, opt-out handling, and clear human ownership before it goes live.

  • Honest sender identity and representation.
  • Consent and opt-out behavior configured to the approved program.
  • Outbound scope approved by the practice.
  • Exceptions and complaints routed to a person.
Not legal advice:

We build sensible technical guardrails, but your counsel should review any outbound calling or texting program for the relevant jurisdiction and client base.

OUR HARD LINES

The things we will never do.

01We never sell or rent your practice data or your clients’ data.
02We never pool your contacts into a list for other practices.
03We never authorize AI to discuss sensitive client financial matters. Those route to a person.
04We never fabricate reviews, testimonials, results, credentials, or security certifications.
05We never lock you out of the website, brand assets, content, or client relationships that are yours.
06We never change how an assistant represents your practice without an approved change.
THE PROOF UNDERNEATH

Verify the real controls. Reject decorative seals.

The visible evidence today is HTTPS delivery, truthful public boundaries, named vendor trust pages, a working AI demo, and a published refusal to claim certifications before they are earned or correctly attributed.

COMMON QUESTIONS

Plain answers, with limits stated.

Is my clients’ data safe with PGT?

The system is designed to minimize sensitive-data exposure: public AI handles approved new-prospect and front-office work, sensitive matters route to the practice, and precise storage, access, and retention details are documented for the actual implementation.

Will AI talk to my clients about their finances?

Not under the default approved scope. AI supports new-prospect intake, scheduling, reviews, and follow-up. Sensitive or account-specific matters route to a person.

Do I own my data and website?

The website, brand assets, content, and client relationships remain yours. System access and handoff responsibilities are documented per engagement.

Are automated calls and texts legally compliant?

We configure consent-aware identity, opt-out, and suppression controls to the approved program and platform requirements. This is not legal advice; your counsel should review outbound programs for your jurisdiction and audience.

Who can access my systems?

Access roles are defined for the actual implementation. We do not publish a blanket access-control claim until the client-specific roles and vendor configuration are documented.

Ask a question in writing →
INVITE THE SCRUTINY

Have a data or security question we didn't cover?

Ask it directly. We will walk through the actual data path, vendors, roles, and boundaries proposed for your practice.

Plain answers, in writing or on a call. That's the standard.