Solutions
Products
Industries
Resources
Admin console
A row of icons displaying Google Workspace products.

Google Workspace security whitepaper

How Google Workspace protects your data

Technology with security at its core

As an innovator in hardware, software, network and system management technologies, Google used the principle “defense in depth” to create an IT infrastructure that is more secure and easier to manage than more traditional technologies. We custom-designed our servers, proprietary operating system and geographically distributed data centers to ensure that Google Workspace runs on a technology platform that is conceived, designed and built to operate securely.

State-of-the-art data centers

Google’s focus on security and protecting data is among our primary design criteria. Our data center physical security features a layered security model, including safeguards like custom-designed electronic access cards, alarms, vehicle access barriers, perimeter fencing, metal detectors, and biometrics, in addition to data center floors that feature laser beam intrusion detection.

Our data centers are monitored 24/7 by high-resolution interior and exterior cameras that can detect and track intruders, with access logs, activity records, and camera footage available in case an incident occurs. Data centers are also routinely patrolled by experienced security guards who have undergone rigorous background checks and training.

The closer you get to the data center floor, the tighter these security measures become. In fact, less than one percent of Google employees will ever set foot in one of our data centers. Those that do have specific roles have been pre-approved and access the floor in the only way possible: through a security corridor that implements multi-factor access control using security badges and biometrics.

Powering our data centers

To keep things running 24/7 and ensure uninterrupted services, Google’s data centers feature redundant power systems and environmental controls. Cooling systems maintain a constant operating temperature for servers and other hardware, reducing the risk of service outages. In case of an incident, every critical component has a primary power source and an equally powerful alternate. Our diesel engine backup generators can provide enough emergency electrical power to run each data center at full capacity. Fire detection and suppression equipment—including heat, fire, and smoke detectors—triggers audible and visible alarms in the affected zone, at security operations consoles, and at remote monitoring desks, helping to prevent hardware damage.

Environmental impact

Google cares deeply about minimizing the environmental impact of our data centers, to the point that we design and build our own facilities using the latest “green” technology. We install smart temperature controls, utilize “free-cooling” techniques like using outside air or reused water for cooling, and redesign how power is distributed to reduce unnecessary energy loss. We constantly gauge how we’re doing by calculating the performance of each facility using comprehensive efficiency measurements.

We’re proud to be the first major Internet services company to gain external certification of our high environmental, workplace safety, and energy management standards throughout our data centers. Specifically, we achieved voluntary ISO 14001, OHSAS 18001 and ISO 50001 certifications, which are all built around a very simple concept: Say what you’re going to do, then do what you say—and then keep improving.

Custom server hardware and software


Google’s data centers house energy-efficient custom, purpose-built servers and network equipment that we design and manufacture ourselves. Our production servers also run a custom-designed operating system (OS) based on a stripped-down and hardened version of Linux. In other words, Google’s servers and their OS are designed for the sole purpose of providing Google services, which means that, unlike much commercially available hardware, Google servers don’t include unnecessary components such as video cards, chipsets, or peripheral connectors, that can introduce vulnerabilities. Google server resources are dynamically allocated, allowing for flexibility in growth and the ability to adapt quickly and efficiently, adding or reallocating resources based on customer demand. This homogeneous environment is maintained by proprietary software that continually monitors systems for binary modifications. If a modification is found that differs from the standard Google image, the system is automatically returned to its official state. These automated, self-healing mechanisms enable Google to monitor and remediate destabilizing events, receive notifications about incidents, and slow down potential network compromises before they become critical issues.

Hardware tracking and disposal

Google uses barcodes and asset tags to meticulously track the location and status of all equipment within our data centers from acquisition and installation, to retirement and destruction. We have also implemented metal detectors and video surveillance to help make sure no equipment leaves the data center floor without authorization. During its lifecycle in the data center, if a component fails to pass a performance test at any point, it is removed from inventory and retired.

Each data center adheres to a strict disposal policy and any variances are immediately addressed. When a hard drive is retired, authorized individuals verify that the disk is erased, writing zeros to the drive and performing a multiple-step verification process to ensure it contains no data. If the drive cannot be erased for any reason, it is stored securely until it can be physically destroyed. This physical destruction is a multistage process beginning with a crusher that deforms the drive, followed by a shredder that breaks the drive into small pieces, which are then recycled at a secure facility.

A global network with unique security benefits

Google’s IP data network consists of our own fiber, public fiber, and undersea cables, enabling us to deliver highly available and low latency services across the globe.

With other cloud services and on-premises solutions, customer data must make several journeys between devices, known as “hops,” across the public Internet. The number of hops depends on the distance between the customer’s ISP and the solution’s data center, and each additional hop introduces a new opportunity for data to be attacked or intercepted. Because it’s linked to most ISPs in the world, Google’s global network can limit the number of hops across the public Internet, improving the security of data in transit.

Defense in depth describes the multiple layers of defense that protect Google’s network from external attacks. It starts with industry-standard firewalls and access control lists (ACLs) to enforce network segregation, and all traffic being routed through custom Google Front End (GFE) servers to detect and stop malicious requests and Distributed Denial of Service (DDoS) attacks. Additionally, GFE servers are only allowed to communicate with a controlled list of servers internally, a “default deny” configuration that prevents GFE servers from accessing unintended resources. Finally, logs are routinely examined to reveal any exploitation of programming errors, and access to networked devices is restricted to authorized personnel. The bottom line? Only authorized services and protocols that meet our security requirements are allowed to traverse our network, anything else is automatically dropped.

Encrypting data in transit and at rest

Encryption is an important piece of the Google Workspace security strategy, helping to protect your emails, chats, video meetings, files, and other data. First, we encrypt certain data as described below while it is stored “at rest”—stored on a disk (including solid-state drives) or backup media. Even if an attacker or someone with physical access obtains the storage equipment containing your data, they won’t be able to read it because they don’t have the necessary encryption keys. Second, we encrypt all customer data while it is “in transit”—traveling over the Internet and across the Google network between data centers. Should an attacker intercept such transmissions, they will only be able to capture encrypted data. We’ll take a detailed look at how we encrypt data stored at rest and data in transit below.

Google has led the industry in using Transport Layer Security (TLS) for email routing, which allows Google and non-Google servers to communicate in an encrypted manner. When you send email from Google to a non-Google server that supports TLS, the traffic will be encrypted, preventing passive eavesdropping. We believe increased adoption of TLS is so important for the industry that we report TLS progress in our Email Encryption Transparency Report. We also improved email security in transit by developing and supporting the MTA-STS standard allowing receiving domains to require transport confidentiality and integrity protection for emails. Google Workspace customers also have the extra ability to only permit email to be transmitted to specific domains and email addresses if those domains and addresses are covered by TLS. This can be managed through the TLS compliance setting.

For further information on encryption, please see our Google Workspace Encryption whitepaper.

Low latency and highly available solution

Google designs all the components of our platform to be highly redundant, from our server design and how we store data, to network and Internet connectivity, and even the software services themselves. This “redundancy of everything” includes error handling by design and creates a solution that is not dependent on a single server, data center, or network connection.

Google’s data centers are geographically distributed to minimize the effects of regional disruptions such as natural disasters and local outages. In the event of hardware, software, or network failure, data is automatically shifted from one facility to another so that, in most cases, Google Workspace customers can continue working without interruption. This also means customers with global workforces can collaborate on documents, video conferencing and more without additional configuration or expense, sharing a highly performant and low latency experience as they work together on a single global network.

Google’s highly redundant infrastructure also helps protect our customers from data loss. For Google Workspace, our recovery point objective (RPO) target is zero, and our recovery time objective (RTO) design target is also zero. We aim to achieve these targets through live or synchronous replication: actions you take in Google Workspace products are simultaneously replicated in two data centers at once, so that if one data center fails, we transfer your data over to the other one that’s also been reflecting your actions.

To do this efficiently and securely, customer data is divided into digital pieces with random file names. Neither the content nor the file names of these pieces are stored in readily human-readable format, and stored customer data cannot be traced to a particular customer or application just by inspecting it in storage. Each piece is then replicated in near-real time over multiple disks, multiple servers, and multiple data centers to avoid a single point of failure. To further prepare for the worst, we conduct disaster recovery drills that assume individual data centers—including our corporate headquarters—won’t be available for 30 days.

Service availability

Some of Google’s services may not be available in some jurisdictions currently or temporarily. Google’s Transparency Report shows recent and ongoing disruptions of traffic to Google products. Our code allows us to observe worldwide traffic patterns over time, enabling us to detect significant changes. We also look into our graphs when we receive inquiries from journalists, activists, or other people on the ground. We provide this data to help the public analyze and understand the availability of online information.


Previous
Download full whitepaperDownload full Whitepaper
Next

Sign up for productivity, collaboration, and AI updates

Afghanistan
Albania
American Samoa
Andorra
Anguilla
Antarctica
Antigua and Barbuda
Argentina
Armenia
Aruba
Australia
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgium
Belize
Benin
Bermuda
Bhutan
Bolivia
Bosnia and Herzegovina
Botswana
Bouvet Island
Brazil
British Indian Ocean Territory
British Virgin Islands
Brunei
Bulgaria
Burkina Faso
Burundi
Cambodia
Cameroon
Canada
Cape Verde
Cayman Islands
Central African Republic
Chad
Chile
China
Christmas Island
Cocos [Keeling] Islands
Colombia
Comoros
Congo [DRC]
Congo [Republic]
Cook Islands
Costa Rica
Croatia
Cyprus
Czech Republic
Côte d’Ivoire
Denmark
Djibouti
Dominica
Dominican Republic
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Ethiopia
Falkland Islands [Islas Malvinas]
Faroe Islands
Fiji
Finland
France
French Guiana
French Polynesia
French Southern Territories
Gabon
Gambia
Georgia
Germany
Ghana
Gibraltar
Greece
Greenland
Grenada
Guadeloupe
Guam
Guatemala
Guinea
Guinea-Bissau
Guyana
Haiti
Heard Island and McDonald Islands
Honduras
Hong Kong
Hungary
Iceland
India
Indonesia
Iraq
Ireland
Israel
Italy
Jamaica
Japan
Jordan
Kazakhstan
Kenya
Kiribati
Kuwait
Kyrgyzstan
Laos
Latvia
Lebanon
Lesotho
Liberia
Libya
Liechtenstein
Lithuania
Luxembourg
Macau
Macedonia [FYROM]
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Micronesia
Moldova
Monaco
Mongolia
Montserrat
Morocco
Mozambique
Namibia
Nauru
Nepal
Netherlands
Netherlands Antilles
New Caledonia
New Zealand
Nicaragua
Niger
Nigeria
Niue
Norfolk Island
Northern Mariana Islands
Norway
Oman
Pakistan
Palau
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Pitcairn Islands
Poland
Portugal
Puerto Rico
Qatar
Romania
Russia
Rwanda
Réunion
Saint Helena
Saint Kitts and Nevis
Saint Lucia
Saint Pierre and Miquelon
Saint Vincent and the Grenadines
Samoa
San Marino
Saudi Arabia
Senegal
Seychelles
Sierra Leone
Singapore
Slovakia
Slovenia
Solomon Islands
Somalia
South Africa
South Georgia and the South Sandwich Islands
South Korea
Spain
Sri Lanka
Suriname
Svalbard and Jan Mayen
Swaziland
Sweden
Switzerland
São Tomé and Príncipe
Taiwan
Tajikistan
Tanzania
Thailand
Timor-Leste
Togo
Tokelau
Tonga
Trinidad and Tobago
Tunisia
Turkey
Turkmenistan
Turks and Caicos Islands
Tuvalu
U.S. Outlying Islands
U.S. Virgin Islands
Uganda
Ukraine
United Arab Emirates
United Kingdom
United States
Uruguay
Uzbekistan
Vanuatu
Vatican City
Venezuela
Vietnam
Wallis and Futuna
Western Sahara
Yemen
Zambia
Zimbabwe
1
2-9
10-19
20-49
50-99
100-199
200-349
350-999
1000-2999
3000+
I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

أريد تلقّي نشرات إخبارية من Google Cloud وWorkspace

أدرك أن بياناتي الشخصية ستتم معالجتها بما يتوافق مع سياسة خصوصية Google.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

Chci dostávat zpravodaje ze služeb Google Cloud a Workspace
Jeg vil gerne modtage nyhedsbreve fra Google Cloud og Workspace

Jeg er indforstået med, at mine personoplysninger behandles i overensstemmelse med Googles privatlivspolitikker.

Ich möchte Newsletter von Google Cloud und Google Workspace erhalten.

Ich bin damit einverstanden, dass meine personenbezogenen Daten gemäß der Datenschutzerklärung von Google verarbeitet werden.

I would like to receive newsletters from Google Cloud and Workspace.
I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

Quiero recibir boletines informativos de Google Cloud y Workspace

Acepto que mis datos personales se procesen de acuerdo con la Política de Privacidad de Google.

Quiero recibir newsletters de Google Cloud y Workspace

Acepto que mis datos personales se traten de acuerdo con la Política de Privacidad de Google.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.
Haluan saada Google Cloudin ja Workspacen uutiskirjeitä

Ymmärrän, että henkilökohtaista dataani käsitellään Googlen tietosuojakäytännön mukaisesti.

I would like to receive newsletters from Google Cloud and Workspace.
Je souhaite recevoir les newsletters de Google Cloud et Workspace

Je comprends que mes données à caractère personnel seront traitées conformément aux Règles de confidentialité de Google.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.
I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

Szeretnék hírleveleket kapni a Google Cloudtól és a Workspace-től
Saya ingin menerima newsletter dari Google Cloud dan Workspace

Saya memahami bahwa data pribadi saya akan diproses sesuai Kebijakan Privasi Google.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

Desidero ricevere newsletter da Google Cloud e Workspace

Ho compreso che i miei dati personali verranno trattati conformemente alle Norme sulla privacy di Google.

אני רוצה לקבל ניוזלטרים מ-Google Cloud ומ-Workspace

ברור לי שהמידע האישי שלי יעובד בהתאם למדיניות הפרטיות של Google.

Google Cloud と Workspace のニュースレターの受信を希望する

私は、私の個人情報が Google のプライバシー ポリシーに沿って取り扱われることを理解しています。

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

Google Cloud 및 Workspace의 뉴스레터를 수신합니다.
This is required

Google 개인정보처리방침에 따라 Google Cloud가 아래와 같이 내 개인정보를 수집, 사용 및 보유하는 데 동의합니다. 귀하가 이에 부동의하는 경우, 본 요청을 위한 절차를 더 진행하실 수 없습니다.

  • 수집되는 항목: (영업 전문가에게 문의, 자료신청 또는 이벤트등록) 이름, 직무, 이메일, 회사 전화번호, 회사 정보, 국가; (뉴스레터 구독 시) 이름, 직무, 회사 이메일, 국가

  • 수집 및 이용 목적 : 문의 처리 및 마케팅 커뮤니케이션 수행

  • 보유 및 이용 기간 : 문의 처리 및 마케팅 커뮤니케이션 종료 시까지 또는 법적 의무 또는 제한된 사업 목적상 필요한 경우 (자세한 내용은 위 개인정보처리방침 참조)

I agree that Google Cloud will collect, use and retain my personal data as below in accordance with Google's Privacy Policy. If you do not agree with this, you cannot proceed further with this request.

  • Collected Items: (for contact to our sales specialist, gated content or event registration) name, job title, company email, business mobile phone, company information, country; (for newsletter subscription) name, job title, company email, country

  • Purpose of collection and use: handling inquiry and conducting marketing communications.

  • Retention and use period: until the end of the inquiry process and marketing communications, or as necessary for legal obligations or limited business purposes (see above privacy policy for more details).

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

Ik wil graag nieuwsbrieven van Google Cloud en Workspace ontvangen

Ik begrijp dat mijn persoonsgegevens worden verwerkt in overeenstemming met het Privacybeleid van Google.

Jeg ønsker å motta nyhetsbrev fra Google Cloud og Workspace

Jeg forstår at mine personopplysninger vil bli behandlet i henhold til Googles personvernregler.

Chcę otrzymywać newslettery od Google Cloud i Workspace

Rozumiem, że moje dane osobowe będą przetwarzanie zgodnie z polityką prywatności Google.

Quero receber newsletters do Google Cloud e do Workspace

Entendo que meus dados pessoais serão processados de acordo com a Política de Privacidade do Google.

Quero receber newsletters do Google Cloud e Workspace

Compreendo que os meus dados pessoais serão processados de acordo com a Política de Privacidade da Google.

I would like to receive newsletters from Google Cloud and Workspace.
Я хочу получать рассылку о Google Cloud и Workspace

Я понимаю, что мои персональные данные будут обрабатываться в соответствии с Политикой конфиденциальности Google.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.
Jag vill få nyhetsbrev från Google Cloud och Workspace

Jag är medveten om att mina personuppgifter behandlas enligt Googles integritetspolicy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

ฉันต้องการรับจดหมายข่าวจาก Google Cloud และ Workspace

ฉันเข้าใจว่าข้อมูลส่วนตัวของฉันจะได้รับการประมวลผลตามนโยบายความเป็นส่วนตัวของ Google

I would like to receive newsletters from Google Cloud and Workspace.
Google Cloud ve Workspace bültenlerini almak istiyorum

Kişisel verilerimin Google'ın Gizlilik Politikası'na uygun olarak işleneceğini anlıyorum.

Я хочу отримувати інформаційні листи від Google Cloud і Workspace

Я розумію, що мої персональні дані оброблятимуться відповідно до Політики конфіденційності Google.

I would like to receive newsletters from Google Cloud and Workspace.

Sign me up to receive news, product updates, event information and special offers about Google Cloud from Google.

I understand my personal data will be processed in accordance with Google’s Privacy Policy.

Tôi muốn nhận bản tin của Google Cloud và Workspace

Tôi hiểu rằng dữ liệu cá nhân của tôi sẽ được xử lý theo Chính sách quyền riêng tư của Google.

我希望收到 Google Cloud 和 Workspace 的最新简报

我理解,我的个人数据将根据 Google 隐私政策进行处理。

我想接收 Google Cloud 和 Workspace 的通訊

我了解我的個人資料將根據 Google 私隱權政策進行處理。

我想收到 Google Cloud 和 Workspace 電子報

我瞭解 Google 會依據其《隱私權政策》處理我的個人資料。