Detailed Security Review
Diligence answers aligned with the Cloud Security Alliance (CSA) CAIQ v4 domains, compiled for procurement audits.
1. Authentication & access management
Is SSO supported?
CompliantGoogle OAuth 2.0 (OIDC) is supported for self-serve users. SAML 2.0 federation is standard on the Enterprise tier. It integrates with Microsoft Entra ID (Azure AD), Okta, Ping Identity, and ADFS.
Is MFA supported?
CompliantWe inherit MFA configurations enforced by your identity providers (SSO/SAML/Google). We do not store passwords, meaning all verification flags run through your existing security checkpoints.
Is role-based access control enforced?
CompliantYes. Workspace-level roles include Owner, Editor, and Viewer. RBAC is verified in application middlewares and database query rules.
Are passwords stored on your side?
CompliantNo. Authentication is fully passwordless via magic email links, Google SSO, and SAML integrations.
2. Data handling & retention
What data do you collect?
CompliantWe collect uploaded code files/queries solely to modernize them. Metadata like transaction counts, workspace configuration, and audit security events are stored. Code structures are never used to train public LLM agents.
Is data deleted on account closure?
CompliantYes. Accounts undergo a 30-day soft-delete period, followed by complete physical erasure from all active servers. Backups are overwritten on a rolling 30-day cycle.
Can data be pinned to a region?
PartialAll data is hosted inside Google Cloud’s us-central1 region. EU region pinning can be set up for Enterprise customers on request.
3. Encryption
Is data encrypted in transit?
CompliantTLS 1.3 is enforced on all ingress APIs. Internal micro-service endpoints communicate via Google’s TLS envelopes. Downgrade requests are blocked.
Is data encrypted at rest?
CompliantAES-256 encryption is applied via GCP defaults. KMS Customer-Managed Encryption Keys (CMEK) can be provisioned on Enterprise.
4. Secure SDLC
Is code reviewed before deployment?
CompliantYes. All codebase modifications require pull request reviews by certified senior developers and clear automated validation pipelines before shipping.
Are dependencies scanned for vulnerabilities?
CompliantYes. Automated scanners inspect dependencies daily. High and critical CVEs trigger build halts and patch requirements.
Diligence & Custom Surveys
Our compliance team reviews and completes custom security spreadsheets within 48 business hours.
