† Vertex AI Search의 GA 이전 서비스는 Google Cloud 비즈니스 제휴 계약(BAA)에 포함되어 있습니다. Vertex AI Search를 사용하여 1996년 건강 보험 이동성 및 책임법(HIPAA) 및/또는 HIPAA에 따른 개정안이나 규정을 준수해야 하는 방식으로 보호 건강 정보를 저장하거나 처리하는 경우, Google과 적절한 BAA를 체결해야 합니다. 자세한 내용은 Google Cloud의 HIPAA 규정 준수를 참조하세요.
보안 제어
Vertex AI Search는 수평적인 보안을 제공합니다. 일부 제어 기능은 미리보기 버전입니다. CMEK 제어 기능은 Enterprise 버전에서만 사용할 수 있습니다.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2024-12-21(UTC)"],[[["\u003cp\u003eVertex AI Search, including both Standard and Enterprise Editions, along with the RAG APIs, are compliant with HIPAA, ISO 27001, 27017, 27018, 27701, SOC 1, SOC 2, and SOC 3 certifications.\u003c/p\u003e\n"],["\u003cp\u003eVertex AI Search offers security controls such as Data Residency (DRZ), VPC Service Controls, and Access Transparency in both Standard and Enterprise editions.\u003c/p\u003e\n"],["\u003cp\u003eThe Enterprise Edition of Vertex AI Search provides Customer-managed encryption keys (CMEK) for enhanced data security, specifically for US and EU multi-region APIs.\u003c/p\u003e\n"],["\u003cp\u003eThe RAG APIs, which include ranking, grounded generation, and check grounding, have VPC Service Controls and Access Transparency in place but do not have Data Residency or Customer-managed encryption keys.\u003c/p\u003e\n"],["\u003cp\u003eA Business Associate Agreement (BAA) with Google is necessary when utilizing Vertex AI Search for storing or processing Protected Health Information (PHI) under HIPAA regulations.\u003c/p\u003e\n"]]],[],null,["# Compliance and security controls\n\nThis page provides a high-level view of the compliance certifications and\nsecurity controls that are supported by Vertex AI Search.\n\nCertifications\n--------------\n\nVertex AI Search and the RAG APIs are compliant as follows:\n\n^\\*^ The RAG APIs are [ranking](/generative-ai-app-builder/docs/ranking), [grounded generation](/generative-ai-app-builder/docs/grounded-gen), and\n[check grounding](/generative-ai-app-builder/docs/check-grounding).\n\n^†^ Vertex AI Search Pre-GA offerings are included in\nthe Google Cloud Business Associate Agreement (BAA). If you will be using\nVertex AI Search to store or process Protected Health Information in a\nmanner subject to the Health Insurance Portability and Accountability Act\n(HIPAA) of 1996 and/or any amendments or regulations under HIPAA, you must enter\ninto an appropriate BAA with Google. For more information, see\n[HIPAA Compliance on Google Cloud](/security/compliance/hipaa).\n\nSecurity controls\n-----------------\n\nVertex AI Search provides security horizontals. The CMEK controls are\nonly available in the Enterprise Edition.\n\n^\\*^ Using external key manager (EKM) or hardware security module\n(HSM) with CMEK is in GA with allowlist.\n\nThe following table identifies security controls for RAG APIs.\n\nWhat's next\n-----------\n\nLearn more about [Google Cloud compliance](/security/compliance)."]]