Managed PostgreSQL, MySQL, and SQL Server on GCP. HIPAA BAA, SOC 2, FedRAMP Moderate (High via Assured Workloads), PCI DSS, ISO 27001. Automatic backups, point-in-time recovery, high-availability with regional failover. The GCP-native managed RDBMS path.
GCP Cloud SQL is Google's managed PostgreSQL, MySQL, and SQL Server on GCP — Commercial, with HIPAA BAA, SOC 2, FedRAMP Moderate (High via Assured Workloads), PCI DSS, ISO 27001. The BAA-signing path for GCP-native Postgres/MySQL workloads.
Mirrors AWS RDS / Azure DB positioning for GCP ecosystem. Substrate = GCP; FedRAMP High requires Assured Workloads (separate envelope). Single-cloud lock-in.
Sub-ms reads.
PG/MySQL SQL.
Cloud IAM + DB-level. Cap rule N/A.
GCP-only. Cap applied.
Cloud Logging metadata.
Cloud Monitoring + Cost + Audit Logs.
GCP attestation. 4/6 -> 4.
Cloud Monitoring + integrations. 4/6 -> 4.
Multi-region replicas. 5/6 -> 4.
PG metadata. 1/6 -> 3.
PG + GCP durability.
Best suited for
Compliance certifications
GCP service-level: HIPAA BAA, SOC 2, FedRAMP Moderate (High via Assured Workloads), PCI, ISO 27001.
Use with caution for
AWS RDS for AWS.
View analysis →Azure for Azure.
View analysis →Role: L1 GCP managed RDBMS.
Upstream: SQL writes.
Downstream: SQL + Cloud Monitoring.
Mitigation: Document GCP-only.
Mitigation: Use Assured Workloads for High; standard GCP for Moderate.
BAA via GCP.
Need Assured Workloads.
OSS PG.
This analysis is AI-generated using the INPACT and GOALS frameworks from "Trust Before Intelligence." Scores and assessments are algorithmic and may not reflect the vendor's complete capabilities. Always validate with your own evaluation.