01
Least-privilege access
Nudle only requests the permissions it needs to do the work you signed up for: read-only Search Console and Analytics reporting access, Analytics Admin edit access for GA4 setup, and Tag Manager edit/version/publish access for approved deploys. You can review every connection and revoke it from your dashboard at any time.
02
Encrypted at rest, encrypted in transit
Every byte that travels between you, your connected platforms, and Nudle is encrypted in transit. Authentication tokens and connected-platform credentials are encrypted at rest with industry-standard symmetric encryption. Plaintext credentials never appear in logs, in support tooling, or in the Nudle dashboard.
03
Every deploy is reviewed before it goes live
Before any change reaches your production site, it passes through an automated safety review. Anything that touches passwords, payment fields, third-party storage, cookies, or arbitrary script injection is rejected outright. Nothing reaches your container that has not cleared that gate.
04
Every deploy is cryptographically signed
Every change Nudle pushes to your stack carries a signature tied to the change ID, your account, and a timestamp. If a tag claims to be from Nudle and the signature does not match, you will know. The verification endpoint is open and runs on demand.
05
An audit trail you control
Every action Nudle takes on your behalf is logged immutably and visible in your dashboard. Drafts, approvals, deploys, rollbacks, kill-switch activations, and access events all appear in one timeline. Export the log as CSV at any time. We never delete an audit row.
06
Email on every deploy
Every change that reaches your site triggers an email to your account admins with the before-and-after summary, the approver, a one-click rollback, and a one-click kill-switch link. A compromised account that triggers an unauthorised deploy alerts the owner within seconds.
07
One button to revoke everything
The kill switch revokes every Nudle access token, pauses every tag we have deployed, and notifies your admins. Available from your dashboard at all times. No support ticket, no waiting period, no apology email required.
08
Anomaly detection
Server-side monitoring runs continuously across every Nudle account. If our automated systems see a pattern that looks unusual for you or for the platform overall, deploys pause and our on-call team is notified.
09
A watchdog for tags we did not deploy
Nudle snapshots your Tag Manager container daily and compares it to the previous version. If a tag appears that we did not deploy and that we cannot attribute to your team, we flag it with a risk assessment so you can investigate. Nudle becomes the watchdog for everyone else who touches your container, including the tags that were there before us.