Read-only integration

Connect Google Cloud to cybersoftware

Read-only OAuth connection. Nine evidence types collected automatically across every accessible project: IAM bindings, service accounts, org policies, audit-log config, logging sinks, storage encryption, KMS keys, and Compute instances.

One connection covers both. Google Cloud and Google Workspace share a single cybersoftware connection — connecting either grants both. If you only use Google Cloud, untick the Workspace scopes on the consent screen and cybersoftware skips the Workspace-only evidence.

Go to dashboard to connect

What we collect

Nine evidence types map to the AICPA Common Criteria controls in your SOC 2 report. Same set every sync, no extras.

EvidenceWhat it showsSOC 2 controls
IAM members
gcp:iam:members
Project-level IAM policy bindings — which roles are granted to which members.CC6.1, CC6.3
Service accounts
gcp:iam:service_accounts
Service accounts per project, with disabled status — privileged non-human inventory.CC6.1, CC6.3
Org policies
gcp:org:policies
Organization policy constraints in effect on each project.CC6.1, CC6.6
Audit logs config
gcp:audit_logs:config
Cloud Audit Logs configuration per project — admin-read / data-access log types.CC7.2
Logging sinks
gcp:logging:sinks
Log sinks per project — centralized log export destinations and filters.CC7.2
Storage buckets
gcp:storage:buckets
Cloud Storage buckets with default encryption (CMEK vs Google-managed).CC6.7, CC6.8
Cloud KMS keys
gcp:cloudkms:keys
Customer-managed Cloud KMS crypto keys across every key ring and location.CC6.7
Compute instances
gcp:compute:instances
Compute Engine VMs per project with shielded-VM and disk-encryption status.CC6.6, CC6.7
2SV status (Cloud Identity)
gcp:org:2sv_status
Cloud Identity 2-Step Verification posture — used when Workspace is not connected.CC6.1, CC6.2

Permissions we request

All scopes are read-only.

cybersoftware never writes to your projects, IAM policies, or resources. No modifications, no deletions, no admin actions — just reads the configuration needed for your SOC 2 evidence.

OAuth scopeWhy we need it
cloud-platform.read-onlyRead IAM bindings, service accounts, org policies, audit-log config, storage buckets, KMS keys, and Compute instances across your projects.
logging.readRead Cloud Logging sink configuration to evidence centralized log export.
cloud-identity.groups.readonlyRead Cloud Identity groups to evidence 2-Step Verification posture when Workspace is not connected.

The same consent screen also requests three Google Workspace scopes. If you don't use Workspace, untick them — cybersoftware only collects the GCP evidence above.

How to connect

Three steps. About a minute start to finish.

  1. 1

    Click Connect in cybersoftware

    On your Integrations tab, click Connect on the Google Cloud card. A disclosure modal lists exactly what cybersoftware will read — for both Google Cloud and Workspace.

  2. 2

    Authorize with Google

    Google opens a new tab with the consent screen. Sign in with an account that has read access to your Google Cloud projects. If you don't use Google Workspace, untick the Workspace scopes — cybersoftware will skip the Workspace-only evidence.

  3. 3

    Click Allow and come back

    Review the read-only scopes, click Allow, and Google redirects you back to cybersoftware. The Google Cloud card flips to Connected and the first sync starts automatically.

How to disconnect

Disconnecting in cybersoftware revokes the Google OAuth grant and stops future evidence pulls. Because Google Cloud and Workspace share one grant, disconnecting either one revokes the shared token — if you have both connected, you'll need to reconnect the other.

  1. In cybersoftware: dashboard → Integrations tab → Google Cloud card → Disconnect.
  2. Optionally, also review and revoke at myaccount.google.com/permissions under Google Account → Security → Third-party access.

Note: previously collected evidence stays attached to your assessment for audit reproducibility. Future syncs simply stop once the grant is revoked.

Troubleshooting

cybersoftware shows "waiting" for more than 2 minutes after I clicked Continue.
Make sure you finished the consent in the other tab and clicked Allow. Then click Refresh in the cybersoftware modal. If the card still doesn't flip, close the modal and click Connect again — the OAuth flow is idempotent.
Some of my projects show no evidence.
cybersoftware collects evidence for the first 100 accessible projects per sync, and only for projects where the connecting account has read access and the relevant APIs are enabled. If a project is missing, confirm the account's IAM role and that Cloud Resource Manager / IAM / Storage / KMS / Logging / Compute APIs are enabled on it.
The consent screen warns the app is unverified.
cybersoftware's Google integration uses a restricted scope (Workspace audit logs) that goes through Google's verification review. If you see an "unverified app" warning, verification is still in progress — contact surya@cybersoftware.com and we'll confirm status.

About a minute from here. cybersoftware handles the rest.

Go to your dashboard
cybersoftware

SOC 2 Type 1 and Type 2 for startups. From assessment to audit ready report. $2,000 one time for platform onboarding, or $4,000 with the SOC 2 Type 1 examination and report included. Then $600 a month on a 12 month term, or $7,000 for the first 12 months in one invoice.
Your first SOC 2 Type 2 audit is included in that term.

© 2026 cybersoftware. All rights reserved.Contact: surya@cybersoftware.com

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms. The audit opinion is theirs alone.
We generate custom policies, evidence checklists, and remediation guidance. You remain responsible for implementing controls and owning audit outcomes. Replace placeholders with your actual controls and have final documents reviewed by qualified professionals before your audit.