1. Introduction
This document outlines the robust security policies and measures implemented for your data when it is ingested and stored in our Google Cloud Storage (GCS) environment. As your trusted partner, we are committed to safeguarding your valuable data within our multi-tenant environment, ensuring confidentiality, integrity, and availability. Our approach is built upon Google Cloud's industry-leading security infrastructure and best practices, tailored to provide secure and isolated storage for each of our enterprise customers. Note: For our enterprise customers we are also happy to enable additional controls, policies as mutually agreed and planned.
2. Data Isolation (Multi-Tenant Architecture)
To ensure the highest level of data segregation and prevent unauthorized access between customers, we utilize a dedicated Google Cloud Storage bucket for each enterprise customer.
Dedicated Resources: Your data will reside in a GCS bucket exclusively provisioned for your organization. This creates a hard security boundary, ensuring that your data is logically and physically separated from other tenants' data.
Independent Configuration: Each dedicated bucket allows us to apply unique and granular security controls, lifecycle policies, and compliance settings specific to your requirements, without impacting other customers.
Simplified Auditing: This clear separation facilitates easier auditing and reporting, as all activities related to your data are confined to your dedicated storage resource.
3. Access Control and Identity Management (IAM)
Access to your data within the GCS landing zone is strictly controlled using Google Cloud's Identity and Access Management (IAM) framework only, adhering to the principle of least privilege. Note: We use Uniform Access Buckets in GCS that are IAM enabled.
Service Accounts for Ingestion: We will establish a dedicated Google Cloud Service Account specifically for your organization's data ingestion process. This service account will be the sole identity authorized to upload data to your designated GCS bucket.
Secure Credential Management: Instead of sharing long-lived keys, we will guide you through setting up Workload Identity Federation. This allows your existing identity system to securely authenticate with Google Cloud, granting temporary, least-privileged access to your service account for data uploads, without ever exposing sensitive credentials.
Strict Role-Based Access Control (RBAC): The service account used for ingestion will be granted only the minimum necessary permissions (storage.objects.create and storage.objects.list) on your specific GCS bucket. It will not have permissions to delete data, modify bucket configurations, or access any other customer's data or resources.
Principle of Least Privilege: All internal access to your data by our personnel or automated systems is also governed by strict IAM policies, ensuring access is granted only on a need-to-know and just-in-time basis for operational purposes. Complete audit trail of all subsequent user activities is retained.
MFA: We enforce MFA for all internal users with access to the GCS buckets.
4. Data Encryption
Your data is protected by robust encryption measures, both at rest and in transit.
Encryption at Rest (Default): All data stored in GCS is automatically encrypted at rest using Google-managed encryption keys. Google Cloud employs advanced encryption standards and practices to protect your data without any action required from your side.
Key Rotation: We enforce automated key rotation policies and update dependent services to use the latest key version.
5. Secure Data Transfer and Connectivity
Data transfer into our GCS landing zone is secured through multiple layers to protect your data in transit.
HTTPS/TLS Encryption: All data uploads to GCS occur over secure, encrypted channels using HTTPS/TLS, protecting your data from eavesdropping and tampering during transit.
Private Connectivity (Recommended): For enhanced security and performance, we recommend establishing private network connectivity where feasible:
VPC Service Controls: Your GCS landing zone is protected by VPC Service Controls, which create a security perimeter around your data. This prevents unauthorized access and data exfiltration, even if an identity with some level of access is compromised. Only specifically authorized service accounts, as defined by our ingress policies, can access the bucket from outside this perimeter.
Cloud Interconnect / Cloud VPN: For direct and private network integration from your on-premises environment, we support connections via Google Cloud Interconnect or Cloud VPN, ensuring your data travels over Google's private network infrastructure rather than the public internet.
6. Continuous Monitoring and Auditing
We maintain vigilant oversight of our GCS buckets to detect and respond to security events promptly.
Comprehensive Logging: Detailed audit logs are collected for all activities within your GCS bucket, including data uploads, downloads, and access attempts. These logs provide a complete, immutable record for security investigations and compliance verification.
Security Command Center: We leverage Konfirmity Security Command Center to continuously monitor for misconfigurations, vulnerabilities, and threats across our entire Google Cloud environment, including all GCS resources.
Data Loss Prevention (DLP) Scanning: To safeguard against unintentional exposure of sensitive information, we utilize OptIQ Cloud Data Loss Prevention (DLP) to scan incoming/output data for predefined or custom sensitive data identifiers (e.g., PII, financial data). This allows us to detect and flag sensitive content if present, providing an additional layer of data protection.
7. Our Commitment
Our commitment to your data security is paramount. We continuously review and update our security policies and practices to align with industry best standards and evolving threat landscapes. Our dedicated security team is responsible for maintaining the integrity and security of the GCS landing zone.