This page provides a high-level view of the compliance certifications and security controls that are supported by Gemini Enterprise. The two components of Gemini Enterprise (Gemini Enterprise and NotebookLM Enterprise) have different compliance certifications and security controls.
Certifications
Gemini Enterprise and the NotebookLM Enterprise are compliant as follows:
Compliance certification | Gemini Enterprise | NotebookLM Enterprise |
---|---|---|
HIPAA | ✔ | ✔ |
FedRAMP | ✔ | |
ISO 27001, ISO 27017, ISO 27018, and ISO 27701 | * | * |
SOC 1, SOC 2, SOC 3 | * | * |
PCI DSS | * | * |
* Compliance certifications at Google Cloud are maintained through a structured internal process featuring regular independent audits for new and existing products. We have a long history of meeting certification requirements, including ISO 27xxx, SOC reports, and PCI DSS. Gemini Enterprise and NotebookLM Enterprise, being built on the same Google Cloud infrastructure as many of our certified products, already inherit a significant number of security and privacy controls and will be included in future certification audits.
Security controls
Gemini Enterprise provides the following security horizontals.
Security controls compliance | Gemini Enterprise | NotebookLM Enterprise |
---|---|---|
Data Residency (DRZ) | ✔ US and EU multi-region APIs only | ✔ US and EU multi-region APIs only |
Customer-managed encryption keys: CMEK for Gemini Enterprise CMEK for NotebookLM Enterprise |
✔ US and EU multi-region APIs only 1 |
✔ US and EU multi-region APIs only 1 |
VPC Service Controls | ✔ | ✔ |
Access Transparency | ✔ US and EU multi-regions only | ✔ US and EU multi-regions only |
1 Using external key manager (EKM) or hardware security module (HSM) with CMEK is in GA with allowlist.
What's next
Learn more about Google Cloud compliance.