Google

google.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
54 / 100D
Procurement decision
Approve with conditions
3 conditions outstanding
  • No clear commitment that your data will not train their models
  • Underlying model providers not named
  • Processing location not disclosed

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Underlying model providers not namedCondition

Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.

What to ask for: Require named providers and model versions, plus notice before any model change.

Processing location not disclosedCondition

Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.

What to ask for: Pin processing regions per data classification in the contract.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

How long do they keep your data?Clear

The Cloud DPA instructs deletion of all remaining Customer Data from Google systems at term end, subject to a deferred-deletion provision.

Evidence
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
delete all remaining Customer Data (including existing copies) from Google’s systems
auto-delete your data, we give you the tools to do it.
!Who else can access your data?Ask the vendor

Google publishes a subprocessor register showing each entity, its activity, and service or region relevance.

Requires written confirmation — see Before you sign ↓

Evidence
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Google and its affiliates engage the third-party entities in the table below to perform limited activities in connection with the Google Cloud Platform Services.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.
!Where is your data processed?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!What happens in a security incident?Ask the vendor

The DPA defines a Data Incident as a breach of Google security leading to destruction, loss, alteration, unauthorised disclosure or access on Google-managed systems.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
means a breach of Google’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data on systems managed by or otherwise controlled by Google.

Key findingsclick a row for the evidence

!Human data-labeling is a disclosed subprocessor activityGap

The register discloses human labelers applying labels to customer-submitted datasets under customer instructions, across named countries.

Datasets sent for labeling are seen by people; which entities and countries apply to a given workload needs confirming.

Question for vendor: Which labeling entities and locations would apply to your data, and how is labeling scoped or excluded?

Evidence
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.
AI governance artefacts are published and datedStrong

AI Principles, annual AI Progress reports since 2019, SAIF, and an AI/ML Privacy Commitment.

Longitudinal, versioned governance beats point-in-time statements.

Evidence
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
Our approach to developing and harnessing the potential of AI is grounded in our founding mission — to organize the world's information and make it universally accessible and useful. We believe our approach to AI must be both bold and responsible.
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
See past AI Progress reports 2025 2024 2023 2022 2021 2020 2019
Secure AI Framework (SAIF) is designed to address top-of-mind concerns for security professionals, like AI/ML model risk management, security, and privacy—helping
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Google and its affiliates engage the third-party entities in the table below to perform limited activities in connection with the Google Cloud Platform Services.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Google and its affiliates engage the third-party entities in the table below to perform limited activities in connection with the Google Cloud Platform Services.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score72
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
Our approach to developing and harnessing the potential of AI is grounded in our founding mission — to organize the world's information and make it universally accessible and useful. We believe our approach to AI must be both bold and responsible.
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
See past AI Progress reports 2025 2024 2023 2022 2021 2020 2019

Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI system15% of the score27
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
Google Unified Security is a context-aware security solution designed to deliver integrated, intelligence-driven, and AI-infused security workflows through Gemini.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Secure AI Framework (SAIF) is designed to address top-of-mind concerns for security professionals, like AI/ML model risk management, security, and privacy—helping
red teaming against generative AI models and applications, and integrate AI into your operations to reduce manual toil and build advanced threat detections.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Change management: not publicly evidenced.

Model10% of the score0
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Not Evidenced

Model provider transparency: not publicly evidenced.

Customer data15% of the score65
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
delete all remaining Customer Data (including existing copies) from Google’s systems
auto-delete your data, we give you the tools to do it.
AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Google and its affiliates engage the third-party entities in the table below to perform limited activities in connection with the Google Cloud Platform Services.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score65
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
means a breach of Google’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data on systems managed by or otherwise controlled by Google.
Independent assurance evidence10% of the score78
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
ISO/IEC 27001 | ISO/IEC 27017 | ISO/IEC 27018 | ISO/IEC 27701 | ISO/IEC 42001 | PCI 3DS Core Security Standard | PCI DSS | PCI PIN Security | SOC 1 | SOC 2 | SOC 3
IRAP (Information Security Registered Assessors Program)

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 42001retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27701retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedFedRAMP Marketplace (fedramp.gov) record — FedRAMPretrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
delete all remaining Customer Data (including existing copies) from Google’s systems
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer is a controller or processor, as applicable, of Customer Personal

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+6Publish Model provider transparency evidenceModel 060
+3Publish Change management evidenceAI System 2747
+3Complete the Customer data treatment disclosureData 6585
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 6585
+2Have Governance & accountability disclosures independently corroboratedOrganisation 7287

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 54 → up to 80 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESGoogleGoogleGeminiGeminiGemini Enterprise Agent PlatformGemini Enterprise Agent P…

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 10 — registry checks and verification ladders, click to view
ISO/IEC 42001Claimed & corroborated

Listed in the Google Cloud compliance offerings catalogue.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IAF CertSearch, Aug 24, 2026: Verified on the registry

ISO/IEC 27001Vendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27018Vendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

SOC 2Vendor claimed only
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

IRAPVendor claimed only

Australian government assessment programme, listed for Google Cloud.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

ISO/IEC 27701Claimed & corroborated

Scope covers the Looker (original) hosted platform offerings ONLY - not Google organisation-wide. Extends to ISO/IEC 27017:2015 and 27018:2019 control objectives within that scope. Certified by Coalfire Certification, Inc. (ANAB).

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IAF CertSearch, Aug 24, 2026: Verified on the registry

FedRAMPClaimed & corroborated

Three certified offerings on the FedRAMP Marketplace: Google Services / GCP (High baseline, JAB, certified since 4 Dec 2019), Google Workspace (since 28 Oct 2021, scope includes Gemini App and Gemini for Workspace), and Gemini for Government (certified 21 Jan 2026, FedRAMP 20x Class B). All in Ongoing Certification phase.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 24, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 19 — click to view
AI Principles — Google AI
AI Documentation · Vendor · retrieved Aug 28, 2026
Cybersecurity solutions: SecOps, intelligence, AI, and cloud security | Google Cloud
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Cloud Data Processing Addendum | Google Cloud
DPA · Vendor · retrieved Aug 28, 2026
Google Cloud Platform Subprocessors | Google Cloud
Subprocessor List · Vendor · retrieved Aug 28, 2026
Your data in Search
Privacy Notice · Vendor · retrieved Aug 28, 2026
Cloud compliance and regulations resources | Google Cloud
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Google Docs: Online document and PDF editor | Google Workspace
Product Documentation · Vendor · retrieved Aug 28, 2026
Control Your Online Safety and Privacy - Google Safety Center
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Cloud Compliance - Regulations & Certifications | Google Cloud
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Google Docs: Online Document & PDF Editor | Google Workspace
Product Documentation · Vendor · retrieved Aug 28, 2026
Google Search
AI Documentation · Vendor · retrieved Aug 28, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 42001
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 27701
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses Google at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.