Data Security Platforms
Research preview. Based on public sources, not deployment testing.
← All platforms

Google Sensitive Data Protection

Compare with…

Discovery produces data profiles, while inspection identifies individual sensitive values. Supported stores differ between these functions, so specify whether the evaluation needs a risk profile or a content scan. [1]

Capabilities

Discovery & classification [1]

Updated 3 sources

Store and control evidence

Read each documented action together with its limits.

Find sensitive data in S3

Discovery produces S3 data profiles and can export sample findings to BigQuery. [3]

S3 profiling requires Security Command Center Enterprise and an AWS connector with discovery permissions. Sample findings are a subset and may omit detected information types. [3]

Find sensitive data in BigQuery

Discovery produces BigQuery profiles at project, table and column level. Inspection returns findings for individual sensitive values. [1]

Inspection is a separate job with configurable sampling. Decide whether the required result is a resource profile or individual findings before selecting the scan. [1]

Build an evaluation test from these claims

Data coverage

Read the scope beside each mark. Support for an environment does not establish every capability in every store.

Microsoft 365
Unconfirmed
AWS
Partial

Discovery supports Amazon S3 through a Security Command Center Enterprise AWS connector with discovery permissions. [1] [3]

Google Cloud
Partial

Discovery covers several Google Cloud stores. Inspection has a different support list, including BigQuery, Cloud Storage and Datastore. [1]

Snowflake and Databricks
Unconfirmed
On-prem shares
Unconfirmed
SaaS apps
Unconfirmed

Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed

Deployment and cost

Pricing

Discovery and inspection use different billing models. [2]

Discovery
Consumption pricing and reserved subscription capacity are available.
Inspection
Inspection is billed separately. Other Google Cloud service charges may apply.

Deployment architecture and operating workload are not published in the reviewed sources.

Questions for the vendor

  1. Does each required store need data profiles, individual inspection findings or both? Demonstrate the selected output.
  2. For S3, identify Security Command Center Enterprise entitlements, AWS connector permissions and the contents exported to BigQuery.
  3. Show which data is sampled or excluded, the processing region and the separate charges for discovery and inspection.

Sources

  1. docs.cloud.google.comReviewed
  2. cloud.google.comReviewed
  3. docs.cloud.google.comReviewed