Gemini

google.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
73 / 100B
Procurement decision
Approve with conditions
1 condition outstanding
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Evidence
Google may log prompts to detect potential abuse and violations of its Acceptable Use Policy and Prohibited Use Policy as part of providing generative AI services to customers.
There is no way to disable the storage of this information if you use Grounding with Google Search.
There is no way to disable the storage of this information if you use Grounding with Google Maps.
This data is stored only in-memory (not at-rest), is isolated at the project level, and has a 24-hour TTL.
To achieve zero data retention, customers must take specific actions within each of these areas:
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days,
Zero data retention may not be possible when using some Advanced AI features.
Prompt logging for abuse monitoring for Google models : As outlined in Section 4.3 "Generative AI Safety and Abuse"
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
delete all remaining Customer Data (including existing copies) from Google’s systems
auto-delete your data, we give you the tools to do it.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

Google states that under the Training Restriction in its Service Specific Terms it will not use customer data to train or fine-tune any AI/ML model without the customer's prior permission or instruction, and that this applies to all managed models on the platform including pre-GA models.

Evidence
Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction.
won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.
!How long do they keep your data?Ask the vendor

Google may log prompts to detect abuse and policy violations as part of providing generative AI services. Customers in scope who require zero data retention must request an exception for abuse monitoring; logging is on by default.

Requires written confirmation — see Before you sign ↓

Evidence
Google may log prompts to detect potential abuse and violations of its Acceptable Use Policy and Prohibited Use Policy as part of providing generative AI services to customers.
There is no way to disable the storage of this information if you use Grounding with Google Search.
There is no way to disable the storage of this information if you use Grounding with Google Maps.
This data is stored only in-memory (not at-rest), is isolated at the project level, and has a 24-hour TTL.
To achieve zero data retention, customers must take specific actions within each of these areas:
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days,
Zero data retention may not be possible when using some Advanced AI features.
Prompt logging for abuse monitoring for Google models : As outlined in Section 4.3 "Generative AI Safety and Abuse"
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
delete all remaining Customer Data (including existing copies) from Google’s systems
auto-delete your data, we give you the tools to do it.
!Who else can access your data?Ask the vendor

Google publishes a Google Cloud Platform subprocessor register naming each third-party entity, the activity it performs, the services and regions it is relevant to, the countries where processing occurs, its registered address, country of registration, company number and ultimate parent company.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
The table shows what activity each entity performs and indicates if an entity is only relevant to a specific Service or Region.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
All AI Solutions, Pre-Trained APIs, AI Platform/Gemini Enterprise Agent Platform (formerly Vertex AI), Generative AI Services and Agentic AI Services
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer may, within 90 days after being notified of the engagement of a New Subprocessor, object by immediately terminating the applicable Agreement for convenience:
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Google and its affiliates engage the third-party entities in the table below to perform limited activities in connection with the Google Cloud Platform Services.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.
!Where is your data processed?Ask the vendor

By default customer data may be processed in any country where Google or its subprocessors maintain facilities, subject to any data location commitments the customer has taken up under the Service Specific Terms and the transfer commitments in the addendum's specific privacy laws appendix.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer Data may be processed in any country where Google or its Subprocessors maintain facilities.
Cached data is used only for improving service performance and adheres to all Data Residency requirements for the selected location and does not violate zero
!What happens in a security incident?Ask the vendor

Google commits to notify the customer promptly and without undue delay after becoming aware of a Data Incident and to take reasonable steps to minimise harm. No maximum notification period is stated anywhere in the addendum.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, and promptly take reasonable steps to minimize harm and secure Customer Data.
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
the nature of the Data Incident including the Customer resources impacted; the measures Google has taken, or plans to take, to address the Data Incident and mitigate its potential risk; the measures, if any, Google recommends that Customer take to address the Data Incident; and details of a contact point where more information can be obtained.

Key findingsclick a row for the evidence

Per-feature retention documented with a stated route to zero data retentionStrong

Google publishes, feature by feature, exactly what the Gemini Enterprise Agent Platform retains and for how long — abuse-monitoring prompt logs, three-day Search grounding logs, thirty-day Maps grounding logs, a 24-hour in-memory cache, request-response logging and the Interactions API store flag — together with the specific action needed to reach zero data retention for each, alongside a contractual restriction on training with customer data.

This is the level of specificity a data-flow assessment needs. Most vendors publish a single sentence about retention; here each retention behaviour is named with its duration, its default state, whether it can be disabled and what to do about it.

Evidence
Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction.
To achieve zero data retention, customers must take specific actions within each of these areas:
There is no way to disable the storage of this information if you use Grounding with Google Search.
There is no way to disable the storage of this information if you use Grounding with Google Maps.
This data is stored only in-memory (not at-rest), is isolated at the project level, and has a 24-hour TTL.
Subprocessors named with activity, jurisdiction and change-notice rightsStrong

Google publishes a subprocessor table giving each entity's activity, in-scope services and regions, countries of processing, registered address, company number and ultimate parent, including Cognizant Worldwide Limited performing data labeling for the Gemini Enterprise Agent Platform in India. New subprocessors carry a thirty-day advance notice with name, location and activities.

Named entities with jurisdictions let a buyer run its own fourth-party checks and assess cross-border exposure, rather than accepting a generic assurance that subprocessors are managed.

Evidence
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
The table shows what activity each entity performs and indicates if an entity is only relevant to a specific Service or Region.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
All AI Solutions, Pre-Trained APIs, AI Platform/Gemini Enterprise Agent Platform (formerly Vertex AI), Generative AI Services and Agentic AI Services
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).
!Evidence covers Google Cloud, not consumer Gemini on google.comGap

This scan was requested against google.com, but the material that carries the commitments — the Cloud Data Processing Addendum, the compliance certification list and the subprocessor register — all attach to Google Cloud agreements and the Gemini Enterprise Agent Platform. Consumer Gemini reached through a personal Google account sits under different terms that were not part of this collection.

None of the protections above follow a user into a consumer account. An organisation can hold a Google Cloud agreement and still have staff pasting material into consumer Gemini, where the training restriction, retention controls and subprocessor commitments established here do not apply.

Question for vendor: Confirm which Google agreement will govern our Gemini use, and whether any staff currently access Gemini through consumer Google accounts rather than through our tenancy.

Evidence
Reasoned inferenceCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
This Cloud Data Processing Addendum (including its appendices, the “ Addendum ”) is incorporated into the Agreement(s) (as defined below) between Google and Customer.
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
SOC 2 and SOC 3 reports produced by Google’s Third-Party Auditor and updated annually based on an audit performed at least once every 12 months
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
The table shows what activity each entity performs and indicates if an entity is only relevant to a specific Service or Region.
!Breach notification is not bound to a maximum periodGap

The Cloud Data Processing Addendum commits Google to notify the customer promptly and without undue delay after becoming aware of a Data Incident, and specifies in detail what that notification must contain, but sets no maximum notification period anywhere in the addendum.

As controller, the customer carries the GDPR Article 33 obligation to notify its supervisory authority within 72 hours of becoming aware of a personal data breach, and comparable duties under other regimes. An unquantified processor deadline cannot be tested against that clock or written into an internal incident-response standard.

Question for vendor: Confirm in writing the maximum period within which Google will notify us of a Data Incident, and whether that period is available as a contractual commitment rather than a service expectation.

Evidence
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, and promptly take reasonable steps to minimize harm and secure Customer Data.
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
the nature of the Data Incident including the Customer resources impacted; the measures Google has taken, or plans to take, to address the Data Incident and mitigate its potential risk; the measures, if any, Google recommends that Customer take to address the Data Incident; and details of a contact point where more information can be obtained.
!Model change and deprecation practice not evidenced in the collected documentsGap

The collected evidence documents configuration-level change control — default states for logging and caching, IAM-gated changes, and a GA versus pre-GA distinction — but contains no model versioning, deprecation or change-notification policy for the Gemini models themselves, and no published model card or evaluation result.

A buyer whose controls are validated against a specific model version needs to know how much notice it gets before that version changes or is withdrawn, and what evidence accompanies a new version.

Question for vendor: Provide the model version, deprecation and change-notice policy for the Gemini models we would use, and the published evaluation or model card for the current version.

Evidence
Request-response logging : This feature is disabled by default. It can be enabled using a configuration setting on a per-model, per-project basis.
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
We identify and assess AI risks through research, expert input, and comprehensive pre- and post-launch testing—which inform our policies and frameworks.
This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
The table shows what activity each entity performs and indicates if an entity is only relevant to a specific Service or Region.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
All AI Solutions, Pre-Trained APIs, AI Platform/Gemini Enterprise Agent Platform (formerly Vertex AI), Generative AI Services and Agentic AI Services
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer may, within 90 days after being notified of the engagement of a New Subprocessor, object by immediately terminating the applicable Agreement for convenience:
To achieve zero data retention for Google trained models, customers must take additional specific actions within each of these areas:
Zero data retention may not be possible when using some Advanced AI features.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Google and its affiliates engage the third-party entities in the table below to perform limited activities in connection with the Google Cloud Platform Services.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score80
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
Guided by our AI Principles, our AI governance is operationalized through a comprehensive and multi-layered approach that spans the entire model lifecycle—from responsible model development and deployment to post-launch monitoring and remediation.
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
Our approach to developing and harnessing the potential of AI is grounded in our founding mission — to organize the world's information and make it universally accessible and useful. We believe our approach to AI must be both bold and responsible.
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
See past AI Progress reports 2025 2024 2023 2022 2021 2020 2019
first in the industry to publish an AI/ML Privacy Commitment , which outlines our belief that customers should have the highest level of security and control over their data that is stored in the cloud.

Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI system15% of the score52
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Covered
Evidence — AI system description
This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.
To achieve zero data retention for Google trained models, customers must take additional specific actions within each of these areas:
Google Unified Security is a context-aware security solution designed to deliver integrated, intelligence-driven, and AI-infused security workflows through Gemini.
first in the industry to publish an AI/ML Privacy Commitment , which outlines our belief that customers should have the highest level of security and control over their data that is stored in the cloud.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedAI Principles — Google AIretrieved Aug 28, 2026
We identify and assess AI risks through research, expert input, and comprehensive pre- and post-launch testing—which inform our policies and frameworks.
Secure AI Framework (SAIF) is designed to address top-of-mind concerns for security professionals, like AI/ML model risk management, security, and privacy—helping
red teaming against generative AI models and applications, and integrate AI into your operations to reduce manual toil and build advanced threat detections.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
Request-response logging : This feature is disabled by default. It can be enabled using a configuration setting on a per-model, per-project basis.
Model10% of the score60
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
To achieve zero data retention for Google trained models, customers must take additional specific actions within each of these areas:
Zero data retention may not be possible when using some Advanced AI features.
won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.
Prompt logging for abuse monitoring for Google models : As outlined in Section 4.3 "Generative AI Safety and Abuse"

Model provider transparency: vendor-evidenced, not yet independently corroborated.

Customer data15% of the score85
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction.
Google may log prompts to detect potential abuse and violations of its Acceptable Use Policy and Prohibited Use Policy as part of providing generative AI services to customers.
There is no way to disable the storage of this information if you use Grounding with Google Search.
There is no way to disable the storage of this information if you use Grounding with Google Maps.
This data is stored only in-memory (not at-rest), is isolated at the project level, and has a 24-hour TTL.
To achieve zero data retention, customers must take specific actions within each of these areas:
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer instructs Google to process Customer Data in accordance with the applicable Agreement (including this Addendum) only as follows:
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days,
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer Data may be processed in any country where Google or its Subprocessors maintain facilities.
won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.
Prompt logging for abuse monitoring for Google models : As outlined in Section 4.3 "Generative AI Safety and Abuse"
Cached data is used only for improving service performance and adheres to all Data Residency requirements for the selected location and does not violate zero
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
delete all remaining Customer Data (including existing copies) from Google’s systems
auto-delete your data, we give you the tools to do it.

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
The table shows what activity each entity performs and indicates if an entity is only relevant to a specific Service or Region.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
All AI Solutions, Pre-Trained APIs, AI Platform/Gemini Enterprise Agent Platform (formerly Vertex AI), Generative AI Services and Agentic AI Services
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will, at least 30 days before the New Subprocessor starts processing any Customer Data, notify Customer of the engagement (including the name, location and activities of the New Subprocessor).
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer may, within 90 days after being notified of the engagement of a New Subprocessor, object by immediately terminating the applicable Agreement for convenience:
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Google and its affiliates engage the third-party entities in the table below to perform limited activities in connection with the Google Cloud Platform Services.
Vendor publishedGoogle Cloud Platform Subprocessors | Google Cloudretrieved Aug 28, 2026
Data Labeling: Human labelers apply labels to datasets submitted by Customer based on instructions provided by Customer. See the Data Labeling Use Cases page for more information.

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the scoreorganisation-level evidence85

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Google will notify Customer promptly and without undue delay after becoming aware of a Data Incident, and promptly take reasonable steps to minimize harm and secure Customer Data.
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
the nature of the Data Incident including the Customer resources impacted; the measures Google has taken, or plans to take, to address the Data Incident and mitigate its potential risk; the measures, if any, Google recommends that Customer take to address the Data Incident; and details of a contact point where more information can be obtained.
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
means a breach of Google’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data on systems managed by or otherwise controlled by Google.

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the scoreorganisation-level evidence100

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
SOC 2 and SOC 3 reports produced by Google’s Third-Party Auditor and updated annually based on an audit performed at least once every 12 months
An independent third-party auditor has granted a formal certification, attestation, or audit report based on an assessment that affirms our compliance with these offerings.
Download reports directly via our Compliance Reports Manager
ISO/IEC 27001 | ISO/IEC 27017 | ISO/IEC 27018 | ISO/IEC 27701 | ISO/IEC 42001 | PCI 3DS Core Security Standard | PCI DSS | PCI PIN Security | SOC 1 | SOC 2 | SOC 3
IRAP (Information Security Registered Assessors Program)

Document held and reviewed by TrustyCyber — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 27, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Legal & contractual10% of the scoreorganisation-level evidence60

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
This Addendum describes the parties’ obligations, including under applicable privacy, data security, and data protection laws, with respect to the processing and security of Customer Data (as defined below).
Cloud service providers can’t provide formal certification of our customers compliance with these laws and regulations.
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer Data may be processed in any country where Google or its Subprocessors maintain facilities.
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer instructs Google to process Customer Data in accordance with the applicable Agreement (including this Addendum) only as follows:
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
delete all remaining Customer Data (including existing copies) from Google’s systems
Vendor publishedCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
Customer is a controller or processor, as applicable, of Customer Personal
Reasoned inferenceCloud Data Processing Addendum | Google Cloudretrieved Aug 28, 2026
This Cloud Data Processing Addendum (including its appendices, the “ Addendum ”) is incorporated into the Agreement(s) (as defined below) between Google and Customer.

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Have Customer data treatment disclosures independently corroboratedData 85100
+3Have Governance & accountability disclosures independently corroboratedOrganisation 8095
+3Have Vulnerability & incident handling disclosures independently corroboratedSecurity Foundation 85100
+2Have Legal & contractual transparency disclosures independently corroboratedLegal Contractual 6075
+2Have Model provider transparency disclosures independently corroboratedModel 6075

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 73 → up to 87 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSINFRASTRUCTURESUBPROCESSORSGoogleGoogleGemini Enterprise Agent PlatformGemini Enterprise Agent P…Gemini modelsGemini modelsGoogle CloudGoogle CloudCognizant Worldwide LimitedCognizant Worldwide Limit…
View as list
Gemini Enterprise Agent Platform Uses AI Service Gemini models
Gemini Enterprise Agent Platform Uses Infrastructure Google Cloud
Gemini Enterprise Agent Platform Contracted Subprocessor Cognizant Worldwide Limited

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 9 — registry checks and verification ladders, click to view
ISO/IEC 42001Claimed & corroborated

Certificate MMIND-24112501, Mastermind Assurance LLC; original registration 25 November 2024, current issuance 10 November 2025, expires 24 November 2027; Statement of Applicability 10 September 2025. The certificate scope names Gemini App (also known as "Gemini"), Gemini Enterprise (incl. Agentspace), Gemini for Google Cloud, Google Workspace with Gemini, Generative AI on Vertex AI and Vertex AI Platform among the in-scope offerings, in the roles of AI Producer and AI Provider - the assessed product is directly in scope, and unlike the ISO/IEC 27001 this certificate covers the consumer Gemini app as well as the enterprise offerings.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Nov 24, 2027

Checked against ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (Google Compliance Reports Manager), Aug 27, 2026: Verified on the registry

ISO/IEC 27001Claimed & corroborated

Certificate 2012-001b, EY CertifyPoint; certified since 11 May 2012, re-issued 12 January 2026, expires 14 May 2027; Statement of Applicability 8 October 2025. The in-scope service list includes Gemini Enterprise (including Agentspace), Gemini for Google Cloud, Gemini Code Assist and the Vertex AI platform services. The certification is explicitly limited to Enterprise Customers, so the consumer Gemini app sits outside the 27001 scope - the ISO/IEC 42001 certificate is the one that covers it.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil May 14, 2027

Checked against ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (Google Compliance Reports Manager), Aug 27, 2026: Verified on the registry

ISO/IEC 27701Claimed & corroborated

Certificate 2021-017, EY CertifyPoint; re-issued 12 January 2026, expires 14 May 2027, tied to the ISO/IEC 27001 certificate 2012-001b and acknowledged only while that certification stands. Google LLC holds it in the role of PII PROCESSOR - the load-bearing fact for a buyer asking who determines the purposes of processing. The in-scope service list includes the Gemini Enterprise offerings, and like the 27001 it is limited to Enterprise Customers.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil May 14, 2027

Checked against ISO/IEC 27701:2019 certificate held in the TrustyCyber vault (Google Compliance Reports Manager), Aug 27, 2026: Verified on the registry

SOC 2Claimed & corroborated

SOC 2 Type 2, Ernst & Young LLP, Google Cloud Platform System, period 1 May 2025 to 30 April 2026, unqualified opinion. Trust services criteria: security, availability, confidentiality and privacy - the TSP section 100 title it cites lists five criteria, but processing integrity is NOT in scope. The in-scope service list includes Gemini Enterprise Agent Platform (formerly Generative AI on Vertex AI), Gemini Enterprise (incl. Agentspace) and Gemini Code Assist, so the assessed product is in scope.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (Google Compliance Reports Manager), Aug 27, 2026: Verified on the registry

ISO/IEC 27018Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil May 14, 2027

Checked against ISO/IEC 27018:2019 certificate 2016-005b held in the TrustyCyber vault (Google Compliance Reports Manager), Aug 28, 2026: Verified on the registry

IRAPVendor claimed only

Australian government assessment programme, listed for Google Cloud.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry

Sources 20 — click to view
AI Principles — Google AI
AI Documentation · Vendor · retrieved Aug 28, 2026
Cybersecurity solutions: SecOps, intelligence, AI, and cloud security | Google Cloud
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Cloud Data Processing Addendum | Google Cloud
DPA · Vendor · retrieved Aug 28, 2026
Google Cloud Platform Subprocessors | Google Cloud
Subprocessor List · Vendor · retrieved Aug 28, 2026
Your data in Search
Privacy Notice · Vendor · retrieved Aug 28, 2026
Cloud compliance and regulations resources | Google Cloud
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Google Docs: Online document and PDF editor | Google Workspace
Product Documentation · Vendor · retrieved Aug 28, 2026
Control Your Online Safety and Privacy - Google Safety Center
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Cloud Compliance - Regulations & Certifications | Google Cloud
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Google Docs: Online Document & PDF Editor | Google Workspace
Product Documentation · Vendor · retrieved Aug 28, 2026
Google Search
AI Documentation · Vendor · retrieved Aug 28, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 27, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 27, 2026
ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (Google Compliance Reports Manager) record — ISO/IEC 42001
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 27, 2026
ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (Google Compliance Reports Manager) record — ISO/IEC 27001
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 27, 2026
ISO/IEC 27701:2019 certificate held in the TrustyCyber vault (Google Compliance Reports Manager) record — ISO/IEC 27701
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 27, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (Google Compliance Reports Manager) record — SOC 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 27, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
ISO/IEC 27018:2019 certificate 2016-005b held in the TrustyCyber vault (Google Compliance Reports Manager) record — ISO/IEC 27018
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.