Vertex AI
google.com
Public evidence identified as at Aug 31, 2026
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
Approve with conditions
A score is only published when there is evidence to score.
Before you sign
Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.
What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“Customer data is retained in Gemini Enterprise Agent Platform for Models as a Service (MaaS) for limited periods of time in the following scenarios and conditions. To achieve zero data retention, customers must take specific actions within each of these areas:”
Why it matters: AI is used but the public sources scanned do not name which foundation models or providers sit in the request path.
What to ask for: Require named providers and model versions, plus notice before any model change.
Why it matters: The public sources scanned do not state where customer data is processed or offer a residency option.
What to ask for: Pin processing regions per data classification in the contract.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Google states it will not use customer data to train or fine-tune any AI/ML models without prior permission or instruction, and that this covers all managed models on the platform including pre-GA models.
“Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.”
!How long do they keep your data?Ask the vendor
Customer data is retained for limited periods in defined situations, and reaching zero data retention requires the customer to act in each of those areas rather than it being the default.
Requires written confirmation — see Before you sign ↓
“Customer data is retained in Gemini Enterprise Agent Platform for Models as a Service (MaaS) for limited periods of time in the following scenarios and conditions. To achieve zero data retention, customers must take specific actions within each of these areas:”
!Who else can access your data?Ask the vendor
Google publishes a Google Cloud Platform subprocessor register showing the relevant service and applicable cloud region for each subprocessor.
Requires written confirmation — see Before you sign ↓
“The GCP Subprocessors tables show the following information for each Subprocessor: Relevant GCP service Applicable Cloud region”
!Where is your data processed?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!What happens in a security incident?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
Confirm in writing: Ask the vendor to state this in writing before signing.
Key findingsclick a row for the evidence
✓A no-training commitment that extends to pre-GA modelsStrong
Google commits not to use customer data to train or fine-tune AI/ML models without prior permission, and states the commitment covers all managed models on the platform including those not yet generally available.
Pre-release models are exactly where training commitments usually carve out, so extending the restriction to them is a substantive addition rather than boilerplate. It is vendor-published, so it belongs in the contract rather than relied on from a documentation page.
“Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.”
!Zero data retention is something you configure, not something you getGap
Customer data is retained for limited periods in defined situations, and the documentation states that achieving zero data retention requires the customer to take specific actions in each of those areas.
Buyers routinely read "zero data retention" as a property of the platform. Here it is an outcome the customer must configure and request, so an organisation assuming it by default would be wrong about where its prompts are held.
Question for vendor: What is the current retention and abuse-logging state for our projects, and has an abuse-monitoring exception been granted?
“Customer data is retained in Gemini Enterprise Agent Platform for Models as a Service (MaaS) for limited periods of time in the following scenarios and conditions. To achieve zero data retention, customers must take specific actions within each of these areas:”
!The product has been renamed by GoogleGap
Google's own Service Specific Terms refer to "Gemini Enterprise Agent Platform (formerly Vertex AI Platform)". This assessment was requested under the former name.
Contract terms already use the new name and documentation is moving to it, so procurement paperwork naming only "Vertex AI" may not match what is being bought. The two names refer to the same platform.
“This restriction does not apply to Gemini Enterprise Agent Platform (formerly Vertex AI Platform) so long as Customer does not use a Google Pre-Trained Model.”
!Assurance evidence is Google Cloud-wide rather than platform-specificGap
Beyond the training restriction and retention documentation, the collected evidence is Google Cloud organisation-level: the DPA, the subprocessor register and the compliance pages. No platform-specific certification scope or security documentation was retrieved.
Organisation-level evidence legitimately applies to the platform, but it cannot answer whether a certificate's scope actually names it. That distinction is where AI assurance usually fails, and it is unresolved here.
Question for vendor: Which certifications name Gemini Enterprise Agent Platform within their scope statements?
“The GCP Subprocessors tables show the following information for each Subprocessor: Relevant GCP service Applicable Cloud region”
?Technical dependency observed: GoogleObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a model provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Google appears to be involved as a model provider: confirm whether this dependency exists, and whether it processes customer data.
“The GCP Subprocessors tables show the following information for each Subprocessor: Relevant GCP service Applicable Cloud region”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“The GCP Subprocessors tables show the following information for each Subprocessor: Relevant GCP service Applicable Cloud region”
AI System Assurance Report Cardscored per assurance object — organisational assurance is not product, model or agent assurance
Derived from the dimensions below — expand any row for the evidence behind its grade.
Organisation & AI governance15% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
Governance & accountability: not publicly evidenced.
AI system15% of the score13
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“This restriction does not apply to Gemini Enterprise Agent Platform (formerly Vertex AI Platform) so long as Customer does not use a Google Pre-Trained Model.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
Testing & evaluation: not publicly evidenced.
Change management: not publicly evidenced.
Model10% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
Model provider transparency: not publicly evidenced.
Customer data15% of the score72
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.”
“Customer data is retained in Gemini Enterprise Agent Platform for Models as a Service (MaaS) for limited periods of time in the following scenarios and conditions. To achieve zero data retention, customers must take specific actions within each of these areas:”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“The GCP Subprocessors tables show the following information for each Subprocessor: Relevant GCP service Applicable Cloud region”
Security foundation15% of the scoreorganisation-level evidence24
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
Vulnerability & incident handling: not publicly evidenced.
Independent assurance evidence10% of the scoreorganisation-level evidence63
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score40
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“This restriction does not apply to Gemini Enterprise Agent Platform (formerly Vertex AI Platform) so long as Customer does not use a Google Pre-Trained Model.”
“Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction. This applies to all managed models on Gemini Enterprise Agent Platform, including GA and pre-GA models.”
Not graded: Agent — not applicable to this scan.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 4 — registry checks and verification ladders, click to view
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 31, 2026: Verified on the registry
Checked against CSA STAR Registry, Aug 31, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Aug 31, 2026: Verified on the registry
Sources 15 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
