← All integrations

Cloud · integration

Google Cloud

IAM, storage exposure, key rotation, audit logging, retention and India residency for a Google Cloud project.

ISO 27001SOC 2PCI DSSCERT-InDPDPARBISEBI CSCRFIRDAI

What ProofLayer proves

Read-only evidence, evaluated against versioned rules.

  • No IAM binding grants access to public principals; project owners are limited
  • Service-account keys are rotated; buckets use uniform access and public-access prevention
  • Data-access audit logs are enabled for all services and logs are retained 180+ days
  • OS Login is enforced, and storage stays in Indian regions (data-residency)

Configure in ProofLayer

Live in minutes.

  1. Connections → New connection → pick this provider and name the account.
  2. Upload the service-account JSON key (stored write-only); only its email is echoed back.
  3. Click Test connection — ProofLayer verifies read access from the control plane and reports a clear reason if anything is off.
  4. Set the scan schedule; every run appends to the evidence chain for this account.
  5. Choose the framework mapping(s) and, optionally, a push target (CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack).

Grant access from your side

Read-only, least-privilege, revocable.

You create the access in your own console and paste a credential ProofLayer stores sealed — it never writes to your systems.

  1. Create a service account and grant it roles/viewer and roles/iam.securityReviewer on the project.
  2. Enable the Resource Manager, IAM, Storage, Compute and Logging APIs.
  3. Add a JSON key and upload it — ProofLayer signs one-hour tokens from it and never returns the key.

In-account agent option. Run the agent on GCE/GKE with Workload Identity and the roles above — no key at all. The collector posts evidence outbound-only, so ProofLayer holds no credential into your environment.

Start

Connect Google Cloud against your next audit.