Create a read-only credential
Create the credential in Google Cloud Platform with the minimum read scope, paste it into devguard, and the connection is live. The integration page in the product spells out the exact permissions.
With a service-account bearer token, devguard verifies your GCP project is reachable and that service-account keys are rotated instead of quietly aging in place.
3 read-only checks, run on a schedule. Each failure becomes a finding linked to a control — every check is listed, none are “coming soon”.
Connectivity check: fails if the service-account token cannot read the project or the project is not in the ACTIVE lifecycle state.
project-reachable
Fails if any user-managed key on the service account is older than the configured maximum age (default 90 days).
service-account-keys-rotated
Fails if a GCP-managed (default) service account has any user-managed keys, which should never exist.
no-user-managed-default-keys
Bring your current platform's test list — we'll map it against these checks, gap by gap
Setup is minutes, not a migration project — and every step stays on your side
Create the credential in Google Cloud Platform with the minimum read scope, paste it into devguard, and the connection is live. The integration page in the product spells out the exact permissions.
The first run starts right after connecting, then repeats on a schedule. Results are timestamped, so your evidence has a history, not a snapshot.
Passing results attach as evidence to the controls they support; failures become findings you triage. When the audit comes, the proof is already connected.
Open any page for its full check register.
You create and scope every credential yourself, and you can revoke it at any time. Checks only read; results and evidence are stored in Switzerland and stay exportable.
Yes. The checks authenticate with a credential you create and scope yourself, and only ever read configuration. devguard holds no write access to Google Cloud Platform and remediates nothing silently.
A failed check becomes a finding linked to the control it supports, with the evidence attached. You decide the treatment — nothing pages your engineers and nothing is auto-remediated.
Checks run from Swiss infrastructure, and results and evidence are stored in Switzerland. Everything is exportable — your evidence stays yours.
Viewer-level roles are enough (roles/viewer, or narrower read roles for IAM). devguard authenticates with a service-account JWT and requests no write permissions.
20 minutes on how you run certification today. Bring your current test or control list and we'll map it against these checks — honestly, gap by gap.