Compliance Reports Manager
Google Cloud’s industry-leading security, third-party audits and certifications, documentation, and contract commitments help support your compliance. Compliance reports manager provides you with easy, on-demand access to these critical compliance resources, at no additional cost. Key resources include our latest ISO/IEC certificates, SOC reports, and self assessments.
Select resources may require sign-in with your Google Cloud or Google Workspace account. If you would like to access previous reports please reach out to support for more information. Anything marked "Google Confidential Information" is shared subject to the confidentiality obligations described in the customer or partner agreement(s) covering Cloud Services. Please contact your sales representative for permission to share confidential resources outside of your organization with customers or other third parties not expressly permitted by your agreement.
| Compliance | Report type | Product area | Last audit |
|---|---|---|---|
|
C5:2020
The Cloud Computing Compliance Controls Catalogue (C5), developed by the German government, assesses the information security of cloud services that leverage internationally recognized security standards such as ISO/IEC 27001 to establish a framework of trust between cloud providers and their customers. |
Audit Report | Google Workspace | Jul 13, 2026 |
|
C5:2020
The Cloud Computing Compliance Controls Catalogue (C5), developed by the German government, assesses the information security of cloud services that leverage internationally recognized security standards such as ISO/IEC 27001 to establish a framework of trust between cloud providers and their customers. |
Audit Report | Google Cloud | Jul 13, 2026 |
|
C5:2020
The Cloud Computing Compliance Controls Catalogue (C5), developed by the German government, assesses the information security of cloud services that leverage internationally recognized security standards such as ISO/IEC 27001 to establish a framework of trust between cloud providers and their customers. |
Audit Report | Apigee Edge | May 22, 2023 |
|
C5:2020
The Cloud Computing Compliance Controls Catalogue (C5), developed by the German government, assesses the information security of cloud services that leverage internationally recognized security standards such as ISO/IEC 27001 to establish a framework of trust between cloud providers and their customers. |
Audit Report | Bare Metal Solution | Feb 27, 2025 |
|
C5:2020
The Cloud Computing Compliance Controls Catalogue (C5), developed by the German government, assesses the information security of cloud services that leverage internationally recognized security standards such as ISO/IEC 27001 to establish a framework of trust between cloud providers and their customers. |
Audit Report | Looker Original | Jul 15, 2026 |
|
CCCS - Protected B High Value Assets (PBHVA): 2025
The CCCS evaluates Google Cloud against comprehensive security control profiles, and a successful assessment demonstrates that a cloud service meets the stringent security requirements necessary to host customer workloads classified up to Protected B. |
Audit Report | Google Cloud | Jan 31, 2025 |
|
CCCS - Protected B Medium (PBMM): 2025
The CCCS evaluates Google Cloud against comprehensive security control profiles, and a successful assessment demonstrates that a cloud service meets the stringent security requirements necessary to host customer workloads classified up to Protected B. |
Audit Report | Google Cloud | May 30, 2025 |
|
CSA Star Level 1: CAIQ Self Assessment
The CSA’s Security, Trust and Assurance Registry Program (CSA STAR) is designed to help customers assess and select a cloud service provider. This CSA STAR Level 1 - Customer Assessment Initiative Questionnaire (CAIQ) is a self-assessment that evaluates a cloud provider against CSA's Cloud Control Matrix. |
Vendor Risk Assessment | Google Workspace | May 31, 2023 |
|
CSA STAR
The CSA’s Security, Trust and Assurance Registry Program (CSA STAR) is designed to help customers assess and select a cloud service provider through a three-step program of self-assessment, third-party audit, and continuous monitoring. |
Audit Report | Google Workspace | Apr 30, 2025 |
|
CSA STAR
The CSA’s Security, Trust and Assurance Registry Program (CSA STAR) is designed to help customers assess and select a cloud service provider through a three-step program of self-assessment, third-party audit, and continuous monitoring. |
Audit Report | Google Cloud | Apr 30, 2025 |
|
CSA STAR
The CSA’s Security, Trust and Assurance Registry Program (CSA STAR) is designed to help customers assess and select a cloud service provider. This CSA STAR Level 1 - Customer Assessment Initiative Questionnaire (CAIQ) is a self-assessment that evaluates a cloud provider against CSA's Cloud Control Matrix. |
Vendor Risk Assessment | Google Cloud | May 31, 2023 |
|
CSA STAR
The CSA’s Security, Trust and Assurance Registry Program (CSA STAR) is designed to help customers assess and select a cloud service provider. This CSA STAR Level 1 - Customer Assessment Initiative Questionnaire (CAIQ) is a self-assessment that evaluates a cloud provider against CSA's Cloud Control Matrix. |
Vendor Risk Assessment | Google Maps Platform | Nov 11, 2025 |
|
CSA STAR
The CSA’s Security, Trust and Assurance Registry Program (CSA STAR) is designed to help customers assess and select a cloud service provider. This CSA STAR Level 1 - Customer Assessment Initiative Questionnaire (CAIQ) is a self-assessment that evaluates a cloud provider against CSA's Cloud Control Matrix. |
Certificate | Google Cloud | Jun 17, 2025 |
|
CSAP
The Cloud Security Assurance Program (CSAP) is a tired certification (e.g. High, Moderate and Low) by the Korea Digital Platform Government Committee and IT Ministry and is mandatory for CSP to enter public sector market in Korea, similar to the US FedRAMP program. |
Certificate | Google Cloud | Jan 21, 2025 |
|
ENS (National Security Framework) Spain
The ENS was established as part of Royal Decree 3/2010 (amended by Decree 951/2015) and serves to establish principles and requirements for the adequate protection of information for Spanish public sector entities. |
Audit Report | Google Workspace | Oct 13, 2019 |
|
ENS (National Security Framework) Spain
The ENS was established as part of Royal Decree 3/2010 (amended by Decree 951/2015) and serves to establish principles and requirements for the adequate protection of information for Spanish public sector entities. |
Certificate | Google Workspace | Oct 17, 2023 |
|
ENS (National Security Framework) Spain
The ENS was established as part of Royal Decree 3/2010 (amended by Decree 951/2015) and serves to establish principles and requirements for the adequate protection of information for Spanish public sector entities. Google Cloud has met the requirements to comply with ENS at the "High" level. |
Audit Report | Google Cloud | Oct 13, 2019 |
|
ENS (National Security Framework) Spain
The ENS was established as part of Royal Decree 3/2010 (amended by Decree 951/2015) and serves to establish principles and requirements for the adequate protection of information for Spanish public sector entities. Google Cloud has met the requirements to comply with ENS at the "High" level. |
Certificate | Google Cloud | Oct 17, 2023 |
|
ETDA
The Information Security Standard for Meeting Control Systems, prescribed by the Thai Ministry of Digital Economy and Society (MDES), is a guideline for providers of meeting control systems (like Google Meet) to establish reliability of the meeting systems, in compliance with MDES’ notification Re: Security Standards of Meetings via Electronic Means, B.E. 2563. Certification against B.E. 2563 is awarded by the Electronic Transaction Development Agency (ETDA). |
Certificate | Google Workspace | Nov 26, 2024 |
|
EU AI Act - Gemini 3 Pro Model Documentation
The EU AI Act is a legal framework that establishes obligations for AI systems based on their potential risks and levels of impact. |
Documentation | Google Cloud | Nov 17, 2025 |
|
GNS - Portugal
The National Security Authority Office of Portugal (GNS) is the accreditation authority for national and international organizations accessing or handling classified information in Portugal. |
Certificate | Google Cloud | May 28, 2025 |
|
GNS - Portugal
The National Security Authority Office of Portugal (GNS) is the accreditation authority for national and international organizations accessing or handling classified information in Portugal. |
Certificate | Google Workspace | May 25, 2025 |
|
GSMA SAS-SM
The GSMA Security Accreditation Scheme for Subscription Management (SAS-SM) enables mobile operators, regardless of their resources or experience, to assess the security of their eUICC suppliers, and of their eUICC subscription management service providers. SAS-SM ensures industry confidence in the security of remote provisioning for eUICCs, a related security auditing and accreditation scheme exists for the providers of eUICC subscription management services. |
Certificate | Google Cloud | Jun 30, 2025 |
|
IRAP Protected
IRAP—the Information Security Registered Assessors Program—provides a framework for assessing the implementation and effectiveness of an organization’s security controls against the Australian government’s security requirements. |
Audit Report | Google Cloud | Jul 27, 2025 |
|
IRAP Protected
IRAP—the Information Security Registered Assessors Program—provides a framework for assessing the implementation and effectiveness of an organization’s security controls against the Australian government’s security requirements. |
Audit Report | Google Workspace | Jul 27, 2025 |
|
ISO 9001
ISO 9001 is the international standard that specifies requirements for a quality management system (QMS). Organizations use the standard to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements |
Certificate | Google Cloud | Aug 11, 2025 |
|
ISO 9001
ISO 9001 is the international standard that specifies requirements for a quality management system (QMS). Organizations use the standard to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements |
Certificate | Google Workspace | Aug 11, 2025 |
|
ISO 9001
ISO 9001 is the global standard, which companies implement to help ensure the quality of products brought to market. |
Certificate | Google Maps Platform | Jul 28, 2026 |
|
ISO 9001
ISO 9001 is the global standard, which companies implement to help ensure the quality of products brought to market. |
Certificate | Looker Original | Jul 15, 2026 |
|
ISO/IEC 27001:2022
This document has been prepared to provide requirements for establishing, implementing, maintaining and continually improving an information security management system. The adoption of an information security management system is a strategic decision for an organization. The establishment and implementation of an organization’s information security management system is influenced by the organization’s needs and objectives, security requirements, the organizational processes used and the size and structure of the organization. All of these influencing factors are expected to change over time. The information security management system preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed. It is important that the information security management system is part of and integrated with the organization’s processes and overall management structure and that information security is considered in the design of processes, information systems, and controls. It is expected that an information security management system implementation will be scaled in accordance with the needs of the organization. This document can be used by internal and external parties to assess the organization’s ability to meet the organization’s own information security requirements. |
Certificate | Bare Metal Solution | May 29, 2025 |
|
ISO/IEC 27001:2022
ISO/IEC 27001 provides the requirements for an information security management system (ISMS), specifies a set of best practices, and details the security controls that can help manage information risks. |
Certificate | Google Cloud | Jan 11, 2026 |
|
ISO/IEC 27001:2022
ISO/IEC 27001 provides the requirements for an information security management system (ISMS), specifies a set of best practices, and details the security controls that can help manage information risks. |
Statement of Applicability | Google Cloud | Oct 7, 2025 |
|
ISO/IEC 27001:2022
ISO/IEC 27001 provides the requirements for an information security management system (ISMS), specifies a set of best practices, and details the security controls that can help manage information risks. |
Certificate | Google Workspace | Jan 11, 2026 |
|
ISO/IEC 27001:2022
ISO/IEC 27001 provides the requirements for an information security management system (ISMS), specifies a set of best practices, and details the security controls that can help manage information risks. |
Statement of Applicability | Google Workspace | Oct 7, 2025 |
|
ISO/IEC 27001:2022
ISO/IEC 27001 provides the requirements for an information security management system (ISMS), specifies a set of best practices, and details the security controls that can help manage information risks. |
Certificate | Google Maps Platform | Jul 28, 2026 |
|
ISO/IEC 27001:2022
ISO/IEC 27001 provides the requirements for an information security management system (ISMS), specifies a set of best practices, and details the security controls that can help manage information risks. |
Certificate | Apigee Edge | Dec 31, 2023 |
|
ISO/IEC 27001:2022
ISO/IEC 27001 provides the requirements for an information security management system (ISMS), specifies a set of best practices, and details the security controls that can help manage information risks. |
Certificate | Looker Original | Jul 15, 2026 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Certificate | Google Workspace | Jan 11, 2026 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Certificate | Google Cloud | Jan 11, 2026 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Certificate | Apigee Edge | Dec 31, 2023 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Statement of Applicability | Google Cloud | Oct 7, 2025 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Statement of Applicability | Google Workspace | Oct 7, 2025 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Certificate | Bare Metal Solution | May 29, 2025 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Certificate | Google Maps Platform | Jul 28, 2026 |
|
ISO/IEC 27017:2015
ISO/IEC 27017:2015 provides guidelines for information security controls applicable to the provision and use of cloud services. |
Certificate | Looker Original | Jul 15, 2026 |
|
ISO/IEC 27018:2019
ISO/IEC 27018 focuses on privacy and security controls for public-cloud service providers that process personally identifiable information (PII). |
Certificate | Google Workspace | Jan 11, 2026 |
|
ISO/IEC 27018:2019
ISO/IEC 27018 focuses on privacy and security controls for public-cloud service providers that process personally identifiable information (PII). |
Certificate | Google Cloud | Jan 11, 2026 |
|
ISO/IEC 27018:2019
ISO/IEC 27018 focuses on privacy and security controls for public-cloud service providers that process personally identifiable information (PII). |
Certificate | Apigee Edge | Dec 31, 2023 |
|
ISO/IEC 27018:2019
ISO/IEC 27018 focuses on privacy and security controls for public-cloud service providers that process personally identifiable information (PII). |
Statement of Applicability | Google Cloud | Jan 9, 2025 |
|
ISO/IEC 27018:2019
ISO/IEC 27018 focuses on privacy and security controls for public-cloud service providers that process personally identifiable information (PII). |
Statement of Applicability | Google Workspace | Jan 9, 2025 |
|
ISO/IEC 27018:2019
ISO/IEC 27018 focuses on privacy and security controls for public-cloud service providers that process personally identifiable information (PII). |
Certificate | Bare Metal Solution | May 29, 2025 |
|
ISO/IEC 27018:2019
ISO/IEC 27018 focuses on privacy and security controls for public-cloud service providers that process personally identifiable information (PII). |
Certificate | Looker Original | Jul 15, 2026 |
|
ISO/IEC 27701:2019
Information technology -- Security techniques Enhancement to ISO/IEC 27001 for privacy management |
Statement of Applicability | Google Cloud | Jan 9, 2025 |
|
ISO/IEC 27701:2019
Information technology -- Security techniques Enhancement to ISO/IEC 27001 for privacy management |
Statement of Applicability | Google Workspace | Jan 9, 2025 |
|
ISO/IEC 27701:2019
ISO/IEC 27701 is the first global privacy standard that focuses on the collection and processing of personally identifiable information (PII). This standard was developed to help organizations comply with international privacy frameworks and laws. |
Certificate | Google Cloud | Jan 11, 2026 |
|
ISO/IEC 27701:2019
ISO/IEC 27701 is the first global privacy standard that focuses on the collection and processing of personally identifiable information (PII). This standard was developed to help organizations comply with international privacy frameworks and laws. |
Certificate | Google Workspace | Jan 11, 2026 |
|
ISO/IEC 27701:2019
ISO/IEC 27701 is the first global privacy standard that focuses on the collection and processing of personally identifiable information (PII). This standard was developed to help organizations comply with international privacy frameworks and laws. |
Certificate | Looker Original | Jul 15, 2026 |
|
ISO/IEC 42001:2023
ISO/IEC 42001:2023 outlines and provides requirements for an Artificial Intelligence Management System (AIMS). |
Certificate | Google Cloud | Nov 9, 2025 |
|
K-ISMS
The Korea-Information Security Management System (K-ISMS) is a regulatory and certification scheme that examines whether an ISMS established, managed, and operated by a domestic company meets certain standards. It was introduced by the Korean government in 2002 and has helped enterprises to establish and operate effective ISMSs. |
Certificate | Google Cloud | Apr 6, 2024 |
|
Multi-tiered Cloud Computing Security Management System (MTCS)
The Multi-Tier Cloud Security (MTCS) Singapore Standard (SS)584 is a cloud security certification managed by the Singapore Info-comm Media Development Authority (IMDA). |
Certificate | Google Cloud | Jul 27, 2025 |
|
Multi-tiered Cloud Computing Security Management System (MTCS)
The Multi-Tier Cloud Security (MTCS) Singapore Standard (SS)584 is a cloud security certification managed by the Singapore Info-comm Media Development Authority (IMDA). |
Certificate | Google Workspace | Jul 27, 2025 |
|
OSPAR V 2.0
The Association of Banks in Singapore established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers which provide information security guidelines for Outsourced Service Providers who wish to provide services to Financial Institutions operating in Singapore. |
Audit Report | Google Cloud | Apr 30, 2024 |
|
OSPAR V 2.0
The Association of Banks in Singapore established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers which provide information security guidelines for Outsourced Service Providers who wish to provide services to Financial Institutions operating in Singapore. |
Audit Report | Google Cloud | Oct 12, 2025 |
|
OSPAR V 2.0
The Association of Banks in Singapore established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers which provide information security guidelines for Outsourced Service Providers who wish to provide services to Financial Institutions operating in Singapore. |
Audit Report | Google Workspace | Oct 12, 2025 |
|
OSPAR
The Association of Banks in Singapore established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers which provide information security guidelines for Outsourced Service Providers who wish to provide services to Financial Institutions operating in Singapore. |
Audit Report | Google Workspace | Apr 30, 2024 |
|
PCI 3-D Secure (PCI 3DS) v1.0
The PCI 3DS Core Security Standard defines physical and logical security requirements for protecting environments where ACS, DS, and/or 3DSS functions are performed. |
Statement of Applicability | Google Cloud | Jun 25, 2026 |
|
PCI 3-D Secure (PCI 3DS) v1.0
PCI 3-D Secure is a security protocol that adds an extra layer of protection to online payments. Google Cloud has undergone a third-party audit to attest to compliance with the PCI 3DS Core Security Standard. |
Audit Report | Google Cloud | Jun 25, 2024 |
|
PCI PIN Security (PCI PIN) v3.1
PCI PIN Security (PCI PIN) contains a complete set of requirements for the secure management, processing, and transmission of personal identification number (PIN) data during online and offline payment card transaction processing at ATMs and point-of-sale (POS) terminals. |
Statement of Applicability | Google Cloud | Jun 25, 2026 |
|
PCI-DSS v3.2
PCI DSS is a set of network security and business best practices guidelines adopted by the PCI Security Standards Council to establish a “minimum security standard” to protect customers’ payment card information. The Attestation of Compliance provides formal assurance from a Qualified Security Assessor (QSA) as to adherence to the PCI DSS. |
Audit Report | Apigee Edge | Jun 14, 2023 |
|
PCI-DSS v4.0.1 (Product Expansion)
PCI DSS is a set of network security and business best practices guidelines adopted by the PCI Security Standards Council to establish a “minimum security standard” to protect customers’ payment card information. The Attestation of Compliance provides formal assurance from a Qualified Security Assessor (QSA) as to adherence to the PCI DSS. |
Audit Report | Google Cloud | May 21, 2026 |
|
PCI-DSS v4.0.1
The Payment Card Industry Data Security Standard (PCI DSS) was developed to encourage and enhance payment card account data security and facilitate the broad adoption of consistent data security measures globally. PCI DSS provides a baseline of technical and operational requirements designed to protect account data. While specifically designed to focus on environments with payment card account data, PCI DSS can also be used to protect against threats and secure other elements in the payment ecosystem. |
Certificate | Bare Metal Solution | Feb 27, 2025 |
|
PCI-DSS v4.0.1
PCI DSS is a set of network security and business best practices guidelines adopted by the PCI Security Standards Council to establish a “minimum security standard” to protect customers’ payment card information. The Attestation of Compliance provides formal assurance from a Qualified Security Assessor (QSA) as to adherence to the PCI DSS. |
Audit Report | Google Cloud | Dec 8, 2025 |
|
PCI-DSS v4.0.1
PCI DSS is a set of network security and business best practices guidelines adopted by the PCI Security Standards Council to establish a “minimum security standard” to protect customers’ payment card information. The Attestation of Compliance provides formal assurance from a Qualified Security Assessor (QSA) as to adherence to the PCI DSS. |
Audit Report | Google Distributed Cloud | Dec 11, 2025 |
|
SNI 27001:2022
Local Indonesia directive based on ISO 27001:2022 |
Certificate | Google Cloud | Oct 9, 2025 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
A SOC 1 report documents a cloud service provider’s internal controls that may be relevant to a customer’s financial reporting. This report is particularly useful for organizations that audit financial statements. |
Audit Report | Google Workspace | Jul 21, 2026 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
A SOC 1 report documents a cloud service provider’s internal controls that may be relevant to a customer’s financial reporting. This report is particularly useful for organizations that audit financial statements. |
Audit Report | Google Cloud | Jul 13, 2026 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
A SOC 1 report documents a cloud service provider’s internal controls that may be relevant to a customer’s financial reporting. This report is particularly useful for organizations that audit financial statements. |
Audit Report | Apigee Edge | May 22, 2023 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
A SOC 1 report documents a cloud service provider’s internal controls that may be relevant to a customer’s financial reporting. This report is particularly useful for organizations that audit financial statements. |
Audit Report | Bare Metal Solution | Feb 27, 2025 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
A SOC 1 report documents a cloud service provider’s internal controls that may be relevant to a customer’s financial reporting. This report is particularly useful for organizations that audit financial statements. |
Audit Report | GCP including (BQ Omni, GCNV, and GCVE) | Jul 21, 2026 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
A SOC 1 report documents a cloud service provider’s internal controls that may be relevant to a customer’s financial reporting. This report is particularly useful for organizations that audit financial statements. |
Audit Report | Looker Original | Jul 15, 2026 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
Bridge letters are attestations made by management of the service provider, in this case, Google Cloud, and are intended to “bridge” the gap from the end date of the SOC report to the customer’s period end date. Bridge letters summarize material changes or issues identified within the internal control environment beyond the period end date of the most recent SOC report. |
Bridge Letter | Google Cloud | Aug 2, 2026 |
|
SSAE18 - SOC 1 (Service Organization Controls Report)
Bridge letters are attestations made by management of the service provider, in this case, Google Cloud, and are intended to “bridge” the gap from the end date of the SOC report to the customer’s period end date. Bridge letters summarize material changes or issues identified within the internal control environment beyond the period end date of the most recent SOC report. |
Bridge Letter | Google Workspace | Aug 2, 2026 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
Bridge letters are attestations made by management of the service provider, in this case, Google Cloud, and are intended to “bridge” the gap from the end date of the SOC report to the customer’s period end date. Bridge letters summarize material changes or issues identified within the internal control environment beyond the period end date of the most recent SOC report. |
Bridge Letter | Google Cloud | Aug 2, 2026 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
Bridge letters are attestations made by management of the service provider, in this case, Google Cloud, and are intended to “bridge” the gap from the end date of the SOC report to the customer’s period end date. Bridge letters summarize material changes or issues identified within the internal control environment beyond the period end date of the most recent SOC report. |
Bridge Letter | Google Workspace | Aug 2, 2026 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | Google Workspace | Jul 21, 2026 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | Google Cloud | Jul 13, 2026 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | Apigee Edge | May 22, 2023 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | AppSheet | Jul 10, 2023 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | Google Maps Platform | Jul 14, 2026 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | Bare Metal Solution | Feb 27, 2025 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | Google Distributed Cloud | Oct 31, 2025 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | GCP including (BQ Omni, GCNV, and GCVE) | Jul 21, 2026 |
|
SSAE18 - SOC 2 AICPA Trust Service Criteria
The purpose of the SOC 2 report is to evaluate an organization’s information systems relevant to security, availability, processing integrity, confidentiality, and privacy. |
Audit Report | Looker Original | Jul 14, 2026 |
|
SSAE18 - SOC 3 AICPA Trust Service Criteria
The SOC 3 report has been developed based on the Auditing Standards Board of the American Institute of Certified Public Accountants’ (AICPA) Trust Service Criteria (TSC). The SOC 3 is a public report of internal controls over security, availability, processing integrity, and confidentiality. |
Audit Report | Google Cloud | Jul 13, 2026 |
|
SSAE18 - SOC 3 AICPA Trust Service Criteria
The SOC 3 report has been developed based on the Auditing Standards Board of the American Institute of Certified Public Accountants’ (AICPA) Trust Service Criteria (TSC). The SOC 3 is a public report of internal controls over security, availability, processing integrity, and confidentiality. |
Audit Report | Google Workspace | Jul 21, 2026 |
|
SSAE18 - SOC 3 AICPA Trust Service Criteria
The SOC 3 report has been developed based on the Auditing Standards Board of the American Institute of Certified Public Accountants’ (AICPA) Trust Service Criteria (TSC). The SOC 3 is a public report of internal controls over security, availability, processing integrity, and confidentiality. |
Audit Report | Apigee Edge | May 22, 2023 |
|
SSAE18 - SOC 3 AICPA Trust Service Criteria
The SOC 3 report has been developed based on the Auditing Standards Board of the American Institute of Certified Public Accountants’ (AICPA) Trust Service Criteria (TSC). The SOC 3 is a public report of internal controls over security, availability, processing integrity, and confidentiality. |
Audit Report | Google Maps Platform | Jul 14, 2026 |
|
SSAE18 - SOC 3 AICPA Trust Service Criteria
The SOC 3 report has been developed based on the Auditing Standards Board of the American Institute of Certified Public Accountants’ (AICPA) Trust Service Criteria (TSC). The SOC 3 is a public report of internal controls over security, availability, processing integrity, and confidentiality. |
Audit Report | Bare Metal Solution | Feb 27, 2025 |
|
SSAE18 - SOC 3 AICPA Trust Service Criteria
The SOC 3 report has been developed based on the Auditing Standards Board of the American Institute of Certified Public Accountants’ (AICPA) Trust Service Criteria (TSC). The SOC 3 is a public report of internal controls over security, availability, processing integrity, and confidentiality. |
Audit Report | GCP including (BQ Omni, GCNV, and GCVE) | Jul 21, 2026 |
|
SSAE18 - SOC 3 AICPA Trust Service Criteria
The SOC 3 report has been developed based on the Auditing Standards Board of the American Institute of Certified Public Accountants’ (AICPA) Trust Service Criteria (TSC). The SOC 3 is a public report of internal controls over security, availability, processing integrity, and confidentiality. |
Audit Report | Looker Original | Jul 15, 2026 |