Encryption At Rest In Google Cloud

This product allows for application-layer encryption managed by the customer. The Tink encryption library supports a wide variety of encryption key types and modes, and these are reviewed regularly to ensure they are current with the latest attacks. Consistent use of a common library means that only a small team of cryptographers needs to implement this tightly controlled and reviewed code — it’s not necessary for every team at Google to “”roll their own”” cryptography. A special Google security team is responsible for maintaining this common cryptographic library for all products.

