Google Sensitive Data Protection
Compare with…Discovery produces data profiles, while inspection identifies individual sensitive values. Supported stores differ between these functions, so specify whether the evaluation needs a risk profile or a content scan. [1]
Discovery & classification [1]
Updated 3 sources
Store and control evidence
Read each documented action together with its limits.
Find sensitive data in S3
Discovery produces S3 data profiles and can export sample findings to BigQuery. [3]
S3 profiling requires Security Command Center Enterprise and an AWS connector with discovery permissions. Sample findings are a subset and may omit detected information types. [3]
Find sensitive data in BigQuery
Discovery produces BigQuery profiles at project, table and column level. Inspection returns findings for individual sensitive values. [1]
Inspection is a separate job with configurable sampling. Decide whether the required result is a resource profile or individual findings before selecting the scan. [1]
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Unconfirmed
- AWS
- Partial
Discovery supports Amazon S3 through a Security Command Center Enterprise AWS connector with discovery permissions. [1] [3]
- Google Cloud
- Partial
Discovery covers several Google Cloud stores. Inspection has a different support list, including BigQuery, Cloud Storage and Datastore. [1]
- Snowflake and Databricks
- Unconfirmed
- On-prem shares
- Unconfirmed
- SaaS apps
- Unconfirmed
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
Pricing
Discovery and inspection use different billing models. [2]
- Discovery
- Consumption pricing and reserved subscription capacity are available.
- Inspection
- Inspection is billed separately. Other Google Cloud service charges may apply.
Deployment architecture and operating workload are not published in the reviewed sources.
Questions for the vendor
- Does each required store need data profiles, individual inspection findings or both? Demonstrate the selected output.
- For S3, identify Security Command Center Enterprise entitlements, AWS connector permissions and the contents exported to BigQuery.
- Show which data is sampled or excluded, the processing region and the separate charges for discovery and inspection.