Limited Use disclosure. How Garde1 handles Google Workspace data.
Garde1’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Google APIs Garde1 accesses
Garde1 connects to the Google Workspace Admin SDK, Drive API, Cloud Identity API, Alert Center API, and Chrome Policy API to collect compliance evidence for CMMC assessments. Access is mostly read-only, but the scopes include admin.directory.user.security, apps.alerts, apps.licensing, and drive.readonly. The exact scopes are shown in the product before you consent; a summary is at garde1.com/security/connector-scopes.
How data is used
Data received from Google APIs is used solely to provide the Garde1 compliance assessment service. Specifically:
- Evidence collection — configuration, inventory, audit log, and policy data is read from your Google Workspace tenant and mapped to CMMC control requirements.
- Compliance evaluation — collected evidence is evaluated against NIST SP 800-171 determination statements to produce Met / Partial / Not Met findings.
- Document generation — findings and configuration facts feed the generated SSP and domain policy documents your organization needs for assessment.
What Garde1 does not do with Google data
- No advertising. Google user data is never used to serve ads, retarget users, or build interest-based profiles.
- No sale or transfer. Google user data is never sold to data brokers, information resellers, or any third party outside what is necessary to provide the assessment service.
- No AI/ML model training. Google user data is never used to develop, improve, or train generalized artificial intelligence or machine learning models.
- No unauthorized human reading. Garde1 personnel do not read Google user data except with your affirmative consent (e.g., for support), for security investigations, for aggregated anonymous reporting, or as legally required.
Data storage and security
Connector credentials (OAuth refresh tokens) are stored in AWS Secrets Manager. Collected data is stored as Google returns it, encrypted at rest, isolated per organization. Full details are in our privacy policy and on the connector scopes page.
Revoking access
You can disconnect the Google Workspace connector at any time inside the Garde1 app. Disconnecting deletes the evidence collected by that connector. It does not revoke the token at Google, so also revoke the app in the Google Admin console under Security > API controls > App access control.
Contact
Questions about Garde1’s use of Google Workspace data: [email protected]