{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"google","name":"Google","domain":"registry.google","category":"Marketing","one_liner":null,"trust_center_url":null,"security_page_url":null,"url":"https://certreports.com/vendors/google/security","last_verified_at":"2026-09-17T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"soc-2","framework_name":"SOC 2","state":"third_party","state_label":"Reported","sentence":"Reported by the CSA STAR registry as of 17 Sep 2026, not confirmed.","kind":"type2","status_text":"CSA STAR Level 2 attestation on the registry, which is built on a SOC 2 examination","issued_at":"2017-02-21","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"csa_star","url":"https://certreports.com/vendors/google/soc-2","evidence":[{"source_type":"registry","source_name":"CSA STAR registry (Level 2 basis)","url":"https://cloudsecurityalliance.org/star/registry/google","fetched_at":"2026-09-17 15:44:42.254747+00","content_hash":"e7f124247f5399c92ba048620a83c0b6cca1f9a2f97419f32566e462a3b1bda7","wayback_url":null,"quote":"google: STAR Level 2 attestation, Trusted Cloud Provider","confidence":1}]},{"framework":"fedramp","framework_name":"FedRAMP","state":"verified_registry","state_label":"Verified","sentence":"Listed in the FedRAMP Marketplace as of 17 Sep 2026.","kind":"authorization","status_text":"FedRAMP Authorized","issued_at":"2026-01-21","expires_at":null,"period_start":null,"period_end":null,"auditor":"Federal Risk and Authorization Management Program","impact_level":"20x Low","as_of":"2026-09-17","under_review":false,"source":"fedramp","url":"https://certreports.com/vendors/google/fedramp","evidence":[{"source_type":"registry","source_name":"FedRAMP Marketplace","url":"https://www.fedramp.gov/marketplace/products/FR2604952026","fetched_at":"2026-09-17 15:44:39.301965+00","content_hash":"395e7ad35dd25d1c547414140161c47ec22827b7ffae3bdbbd5256c38a3b940f","wayback_url":null,"quote":"Google - Gemini for Government: FedRAMP Authorized","confidence":1}]},{"framework":"pci-dss","framework_name":"PCI DSS","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Visa Global Registry of Service Providers as of 17 Sep 2026.","kind":"attestation","status_text":"Listed on the Visa Global Registry as PCI DSS validated through 2026-12-31","issued_at":"2006-07-31","expires_at":"2026-12-31","period_start":null,"period_end":null,"auditor":"MegaplanIT Holdings LLC","impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"visa_grsp","url":"https://certreports.com/vendors/google/pci-dss","evidence":[{"source_type":"registry","source_name":"Visa Global Registry of Service Providers","url":"https://www.visa.com/splisting/","fetched_at":"2026-09-17 15:58:01.686558+00","content_hash":"993a0b25ffcee435432d2b6769f9e5ba34c37ecb17976b6a6bd877f3a76d0e2b","wayback_url":null,"quote":"Google, LLC: PCI DSS, assessor MegaplanIT Holdings LLC, valid through 2026-12-31","confidence":1}]},{"framework":"csa-star","framework_name":"CSA STAR","state":"verified_registry","state_label":"Verified","sentence":"Listed in the CSA STAR registry as of 17 Sep 2026.","kind":"level2","status_text":"STAR Level 2 attestation, Trusted Cloud Provider","issued_at":"2017-02-21","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"csa_star","url":"https://certreports.com/vendors/google/csa-star","evidence":[{"source_type":"registry","source_name":"CSA STAR registry","url":"https://cloudsecurityalliance.org/star/registry/google","fetched_at":"2026-09-17 15:44:42.254747+00","content_hash":"e7f124247f5399c92ba048620a83c0b6cca1f9a2f97419f32566e462a3b1bda7","wayback_url":null,"quote":"google: STAR Level 2 attestation, Trusted Cloud Provider","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Data Privacy Framework list as of 17 Sep 2026.","kind":"listing","status_text":"Active: UK Extension Certification, EU-US Certification, SW-US Certification","issued_at":"2016-09-22","expires_at":"2027-09-13","period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/google/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/5780","fetched_at":"2026-09-17 15:49:09.802448+00","content_hash":"50922bda3ea12ee0eec0cd2975f6a0115b805ce9e3a0da4a64d2ce9631e870c9","wayback_url":null,"quote":"Google LLC: Active: UK Extension Certification, EU-US Certification, SW-US Certification","confidence":1}]}],"brief":{"summary":"As of 17 Sep 2026, Google is listed in the CSA STAR registry with a Level 2 attestation issued 21 Feb 2017, which the registry notes is built on a SOC 2 examination. As of 17 Sep 2026, Google is listed in the FedRAMP registry as FedRAMP Authorized, with authorization dated 21 Jan 2026. As of 17 Sep 2026, Google is listed in the Visa Global Registry of Service Providers as PCI DSS validated through 31 Dec 2026, with the underlying validation originally issued 31 Jul 2006 and audited by MegaplanIT Holdings LLC. As of 17 Sep 2026, Google is listed in the EU-US Data Privacy Framework registry with active EU-US, SW-US, and UK Extension certifications, originally issued 22 Sep 2016 and running through 13 Sep 2027. No public evidence found for HIPAA in the supplied rows as of 17 Sep 2026.","bullets":["CSA STAR (as of 17 Sep 2026): listed in CSA STAR registry, Level 2 attestation issued 21 Feb 2017, noted as built on a SOC 2 examination.","FedRAMP and PCI DSS (as of 17 Sep 2026): listed in FedRAMP registry as FedRAMP Authorized (21 Jan 2026); listed in Visa Global Registry as PCI DSS validated through 31 Dec 2026.","EU-US Data Privacy Framework (as of 17 Sep 2026): listed in DPF registry with active EU-US, SW-US, and UK Extension certifications, valid through 13 Sep 2027."],"model":"claude-sonnet-5","generated_at":"2026-09-17 18:35:38.687746+00"},"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-18T16:34:13.588Z"}