GCP

Integration

Continuous GCP monitoring, automated evidence, assured compliance.

Faster SOC 2

Overview

ComplyJet’s Google Cloud integration delivers real-time visibility across your entire GCP estate—Compute Engine, Cloud Run, App Engine, Cloud SQL, Storage, Pub/Sub, Datastore / Firestore, IAM, and more. We stream configuration and runtime data straight from GCP, map it to 20 + security and privacy frameworks (SOC 2, ISO 27001, GDPR, HIPAA, etc.), and flag drift the moment it happens—so you stay audit-ready without spreadsheets. Designed for fast-moving SaaS teams, ComplyJet turns every project and region into a single, always-up-to-date source of compliance truth.

Supported GCP Resources

ComplyJet monitors these core Google Cloud services—covering compute, storage, databases, messaging, serverless, and identity—for full-stack, always-on visibility.

  • GCP Compute Engine
  • GCP Cloud Storage
  • GCP Cloud SQL
  • GCP Cloud Tasks
  • GCP Datastore / Firestore
  • GCP Pub/Sub – Topics & Subscriptions
  • GCP IAM
  • GCP App Engine (and App Engine Services)
  • GCP Cloud Run Jobs
  • GCP Cloud Run Services

Supported Automated Tests

ComplyJet runs 30 + pre-built, continuously-executing tests across your GCP environment—spanning identity, network, data, logging, and benchmark alignment—to catch misconfigurations in real time.

  • Access-account MFA enabled
  • Account access removed on termination
  • Storage buckets versioned
  • Bigtable cluster CPU monitored & alarmed
  • Bigtable cluster storage monitored & alarmed
  • App Engine CPU utilization monitored & alarmed
  • Daily backups enabled (GCP)
  • Cloud SQL CPU monitored & alarmed
  • Cloud SQL I/O throughput monitored & alarmed
  • Cloud SQL memory monitored & alarmed
  • Firestore read operations monitored & alarmed
  • Datastore request count monitored & alarmed
  • Cloud SQL storage monitored & alarmed
  • Firestore write operations monitored & alarmed
  • Bigtable encrypted at rest
  • Cloud SQL encrypted at rest
  • Datastore encrypted at rest
  • Firestore encrypted at rest
  • Cloud Storage encrypted at rest
  • Logging sink retention configured
  • Cloud Storage public access restricted
  • Compute Engine public ports restricted
  • App Engine public SSH denied
  • Compute Engine public SSH denied
  • Compute Engine CPU utilization monitored & alarmed
  • Pub/Sub subscription age monitored & alarmed
  • Unique access accounts enforced
  • Compute Engine VPC assignment verified
  • VPC flow logs enabled