Encrypted in transit and at rest
Customer data is encrypted in transit over TLS and encrypted at rest through managed-provider protections. Designated third-party integration credentials receive an additional Google Cloud KMS protection layer with versioned, purpose-bound keys.