Growth Legend

Security

Read-only by design. Nothing to breach.

An agency audit needs a collaborator seat that can see every customer you have. This audit needs a read-only API key and never requests a profile. Here is exactly what it touches, in the order it touches it, so your security review takes ten minutes instead of a quarter.

0customer profiles requested, ever
Read-onlythe only key type it accepts
0 sthe key lives after the run ends
90 daysthen the report is deleted
Noneapps installed, webhooks, or writes

The key

What the key can and cannot do.

What it is

A Klaviyo private API key you create with the Read-only key preset. Klaviyo scopes it server-side: read on every resource, write on none. The audit checks the prefix and length before it does anything, and rejects a full-access key's behaviour by never calling a write endpoint in the first place.

How it travels

From your browser to our function over TLS 1.2+, as one field in one POST. It is held in memory for the duration of the run (typically under three minutes), sent to Klaviyo in the Authorization header of each read, and dropped when the function returns. It is never written to a database, a file, a queue, or a log. Error logging strips anything that matches a key pattern before it is written.

What you should do after

Nothing is required. If your policy prefers it, delete the key in Klaviyo (Settings → API keys) the moment the report appears. The report does not depend on the key and keeps working.

What it never asks for

Profiles, events, or any endpoint that returns an individual person. No profiles:read call is made even though a read-only key would allow it. Segment and list membership is read only as a count. Message bodies are not fetched; flow message names and subject lines are.

What is read

Every endpoint, in order.

Each row is a read on Klaviyo's public API, revision 2026-07-15. Nothing else is called. The report tells you how many reads it made and which, if any, were refused.

StepEndpointScopeWhat comes back
1GET /api/accountsaccounts:readAccount name, industry, timezone, currency. Confirms the key.
2GET /api/metricsmetrics:readMetric names and integrations, to find Placed Order and Started Checkout.
3POST /api/metric-aggregatesmetrics:readAggregate counts and values of Placed Order by month, by attributed channel and by flow. Counts only, never events.
4GET /api/flows, GET /api/flows/{id}/flow-actionsflows:readFlow names, status, triggers, delays, message names and subject lines. Live flows only for actions, up to 80.
5POST /api/flow-values-reportsflows:readNinety days of recipients, deliveries, opens, clicks, conversions, revenue, unsubscribes, complaints, bounces per flow.
6GET /api/campaignscampaigns:readCampaigns created in the last 120 days: names, subjects, audiences (as IDs), send settings.
7POST /api/campaign-values-reportscampaigns:readThe same ninety-day statistics per campaign.
8GET /api/lists, GET /api/lists/{id}lists:readList names and opt-in type; a profile count for up to four main lists.
9GET /api/segments, GET /api/segments/{id}segments:readSegment names and definitions (the conditions, not the members); a count for up to five.
10GET /api/forms, POST /api/form-values-reportsforms:readForm names and status; ninety days of views and submits.

Reads respect Klaviyo's published rate limits and back off on a 429. Nothing here affects sending, segments, or your account's own limits beyond the handful of report pulls Klaviyo allows per minute.

What is kept

The report, your email, the date. That's the list.

01

Stored

The finished report (aggregates, names of flows, campaigns, lists, segments and forms, the findings) and the work email and brand you typed. Stored in a private object store under a 96-bit random ID. Encrypted at rest by the provider; the key that protects the store is not the one that serves the site.

02

Not stored

The API key. Any customer profile, email address, phone number, or event. Message bodies. Your IP address in relation to the report (the hosting provider keeps standard access logs for a short period, as every host does).

03

Deleted

Reports are deleted 90 days after creation. Earlier on request: email andrew@growthlegend.com from the address you used and it is gone within two business days, with confirmation.

Subprocessors

Two, and you already use one of them.

WhoWhatWhere
Klaviyo, Inc.The API the audit reads. Your existing agreement governs it.United States
Vercel, Inc.Hosting, the audit function, and the private object store for reports.United States

Google Fonts serves the two typefaces on this site and sees the requesting IP. No analytics, advertising or session-recording script runs here.

For procurement

The questions a security review asks.

Will you sign an NDA or a DPA?

Yes, on request, and we'll say up front what it covers: the only personal data the audit processes is the work email of the person who runs it. Nothing about your customers passes through it.

Does it install anything in Klaviyo?

No. No app, no integration, no webhook, no OAuth grant. Nothing appears in your Integrations page. The only artefact in your account is the key you created, which you control.

Can it change or send anything?

No. The key type cannot, and the software contains no write call. Every endpoint it uses is listed above.

Can our agency run it on our behalf?

Yes, with a read-only key you issue to them. One key per account; a portfolio can be run in one sitting on the enterprise page.

Where is the audit log?

The report is the log: it states the number of reads, the time taken, and every read that was refused or skipped. On request we'll provide the function's request trace for your run.

Is there an account or login to secure?

No accounts exist. Reports live at unguessable links; there is no password to leak and no user database to breach. Treat the link like a document: share it with the people who should see it.

Who built it and who can see the reports?

Andrew Lauchner, who runs Growth Legend. He is the only person with access to the report store, and he opens a report when its owner asks a question about it.

Ten minutes of security review

Then two minutes for the audit.