Configured for the practice
The implementation, data paths, users, and handoffs are documented for the actual client. We do not publish a stronger isolation claim until its platform configuration is verified.
You protect sensitive financial information for a living, so we will not insult you with vague reassurances. This page states the operating posture, the boundaries we keep, what is verified today, and what we refuse to claim without evidence.
Your data stays yours. AI works inside an approved front-office scope. Sensitive matters move to a person.
The implementation, data paths, users, and handoffs are documented for the actual client. We do not publish a stronger isolation claim until its platform configuration is verified.
The public site uses HTTPS. Connected vendor traffic is expected to use authenticated encrypted transport according to each integration.
Your website, brand assets, content, and client relationships remain yours. Handoff responsibilities are documented in the engagement.
Practice data is used to operate the website, assistants, CRM, and approved workflows—not sold, rented, or repurposed as a shared marketing list.
Assistants support approved new-prospect intake, scheduling, reviews, follow-up, and admin. They do not handle sensitive client matters under the default scope.
Roles and permissions depend on the platforms and the client configuration. We document who needs access, what they need it for, and where authentication lives rather than making a universal least-privilege claim without evidence.
No certification badges are displayed without verification. PGT does not claim SOC 2, ISO 27001, HIPAA, PCI, or similar certification on this page.
Automated calls and texts are regulated. The workflow should use approved sender identity, consent and suppression rules, opt-out handling, and clear human ownership before it goes live.
We build sensible technical guardrails, but your counsel should review any outbound calling or texting program for the relevant jurisdiction and client base.
The visible evidence today is HTTPS delivery, truthful public boundaries, named vendor trust pages, a working AI demo, and a published refusal to claim certifications before they are earned or correctly attributed.
The system is designed to minimize sensitive-data exposure: public AI handles approved new-prospect and front-office work, sensitive matters route to the practice, and precise storage, access, and retention details are documented for the actual implementation.
Not under the default approved scope. AI supports new-prospect intake, scheduling, reviews, and follow-up. Sensitive or account-specific matters route to a person.
The website, brand assets, content, and client relationships remain yours. System access and handoff responsibilities are documented per engagement.
We configure consent-aware identity, opt-out, and suppression controls to the approved program and platform requirements. This is not legal advice; your counsel should review outbound programs for your jurisdiction and audience.
Access roles are defined for the actual implementation. We do not publish a blanket access-control claim until the client-specific roles and vendor configuration are documented.
Ask it directly. We will walk through the actual data path, vendors, roles, and boundaries proposed for your practice.
Plain answers, in writing or on a call. That's the standard.