Ezen

Security

Google access is scoped to the user and assistant.

Ezen is designed so a user can see what is connected, which assistant can use it, and how to revoke or delete access.

Agent isolation

A Google connection is assigned to the assistant that requested it. Other assistants do not receive that connection unless the account owner explicitly connects or assigns it.

Short-lived connection links

Agent-specific connection links are one-time requests with a short expiry window. Invalid, expired, or reused links do not create assignments.

Encrypted credential storage

OAuth tokens are stored in the configured encrypted credential store. The Ezen web app stores user identity, ownership metadata, and audit events, not raw Google access tokens.

User controls

Users can remove a single service from Ezen, remove all data and revoke Ezen's access at Google, or revoke Ezen from Google Account permissions.

Data use limits

Ezen uses Google user data only to provide user-facing assistant workflows requested by the user. Ezen does not sell Google user data, does not use it for advertising, and does not use it to train generalized AI models.