Google API Services

Limited Use disclosure. How Garde1 handles Google Workspace data.

Garde1’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Google APIs Garde1 accesses

Garde1 connects to the Google Workspace Admin SDK, Drive API, Cloud Identity API, Alert Center API, and Chrome Policy API to collect compliance evidence for CMMC assessments. Access is mostly read-only, but the scopes include admin.directory.user.security, apps.alerts, apps.licensing, and drive.readonly. The exact scopes are shown in the product before you consent; a summary is at garde1.com/security/connector-scopes.

How data is used

Data received from Google APIs is used solely to provide the Garde1 compliance assessment service. Specifically:

What Garde1 does not do with Google data

  • No advertising. Google user data is never used to serve ads, retarget users, or build interest-based profiles.
  • No sale or transfer. Google user data is never sold to data brokers, information resellers, or any third party outside what is necessary to provide the assessment service.
  • No AI/ML model training. Google user data is never used to develop, improve, or train generalized artificial intelligence or machine learning models.
  • No unauthorized human reading. Garde1 personnel do not read Google user data except with your affirmative consent (e.g., for support), for security investigations, for aggregated anonymous reporting, or as legally required.

Data storage and security

Connector credentials (OAuth refresh tokens) are stored in AWS Secrets Manager. Collected data is stored as Google returns it, encrypted at rest, isolated per organization. Full details are in our privacy policy and on the connector scopes page.

Revoking access

You can disconnect the Google Workspace connector at any time inside the Garde1 app. Disconnecting deletes the evidence collected by that connector. It does not revoke the token at Google, so also revoke the app in the Google Admin console under Security > API controls > App access control.

Contact

Questions about Garde1’s use of Google Workspace data: [email protected]