We are introducing a new option which can make the initial setup of Google Workspace Client-side encryption (CSE) significantly easier and faster for admins.
CSE now supports a simple setup path in the Admin console which can help customers get up and running with CSE in minutes. By combining Cloud HSM Keys with Google Identity, we have automated much of the setup flow which could be time consuming. In a few clicks, admins can set up and deploy CSE, reducing the time to live and allowing customers to use their existing GCP resources to add CSE protection to your most sensitive data.
Customers use Client-side encryption across Workspace applications to encrypt emails, files, meetings and events, to comply with sovereignty and compliance regulations from HIPAA to ITAR. With Client-side encryption, data is encrypted by customer keys before it ever reaches Google servers, making the customer the sole arbiter of their data. Previously, this privacy control required deep technical knowledge to set up a third-party key service and configure an identity provider. With simple setup, admins from enterprise to small businesses can start encrypting their important data within minutes.
For admins who require more custom configurations leveraging third-party key services, that option is also still available via the standard CSE setup process.
Getting started
- Admins: Visit the Help Center to learn more about client-side encryption or setting up CSE with the simplified method.
- End users: No end user action needed.
Rollout pace
- Rapid Release and Scheduled Release domains: Available now
Availability
- Enterprise: Enterprise Plus with the Assured Controls or Assured Controls Plus add-on
Resources
- Google Workspace Admin Help: Set up Client-side encryption (simplified method)
- Cloud Blog: Now available: Cloud HSM as an encryption key service for Workspace client-side encryption
