我们不会公开您发送的文档,也不会将其分享给任何其他人,除非是为了提供 Document AI 服务而需要这样做。例如,有时我们可能需要使用第三方供应商来帮助我们提供服务的某些方面,例如存储或传输数据。我们的供应商须承担相应的安全和保密合同义务。我们不会出于任何其他目的将您发送的文档分享给其他方或公开。
Google 会将我发送给 Document AI 的文档、相应结果或与请求相关的其他信息存储在其服务器上多长时间,以及存储在何处?我可以访问吗?
当您使用批量请求将文档发送到 Document AI 时,我们必须在短期内存储该文档(使用临时密钥加密,这意味着没有人可以访问该文档),以便执行分析并将结果返回给您。对于批量操作,存储的文档通常会在处理完成后立即删除,且具有一天的故障安全存留时间 (TTL)。如果批处理异常终止,数据可能会保留,TTL 最长为一天。
同步流程
对于在线(立即响应)操作,文档数据(在请求中发送)会在内存中处理,在传输过程中加密,不会永久存储到磁盘。Google 还会暂时记录一些关于您的 Document AI API 请求的元数据(例如收到请求的时间和请求的大小),以改善我们的服务和打击滥用行为。
不可以,您不得转售 Document AI 服务。但是,您仍然可以将 Document AI 集成到具有独立价值的应用中。
客户如何控制 Google Cloud 支持人员对其文档或数据的访问权限?
所有 Document AI 解析器都支持 Access Transparency 和访问权限审批。默认情况下,Google 支持人员无法访问任何客户数据或应用。如果 Google 支持团队需要访问客户数据,客户可以使用访问权限审批流程来授权访问数据或应用。此流程从在 Google 支持门户中创建支持服务工单开始。然后,客户会收到一封通知(通常是电子邮件),其中包含授权或拒绝访问的选项。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-18。"],[[["\u003cp\u003eDocument AI prioritizes data security by utilizing Google Cloud's security measures, supporting features like Data Residency, VPC Service Controls, Access Transparency, and Customer-Managed Encryption Keys (CMEK).\u003c/p\u003e\n"],["\u003cp\u003eDocument AI maintains compliance with various standards, including ISO 27001, ISO 27017, ISO 27018, SOC 2, SOC 3, PCI DSS, FedRAMP High, and HIPAA.\u003c/p\u003e\n"],["\u003cp\u003eGoogle does not use customer data to improve Document AI models, nor does it share or publicly expose customer documents, except when necessary for service provision with third-party vendors who are under strict confidentiality agreements.\u003c/p\u003e\n"],["\u003cp\u003eDocuments sent via batch requests are stored briefly, encrypted with an ephemeral key, and typically deleted immediately after processing, while data from online requests is processed in memory and not persisted to disk, though some metadata may be logged temporarily.\u003c/p\u003e\n"],["\u003cp\u003eCustomers are required to redact Personally Identifiable Information (PII) before sharing documents with Google for support purposes, and can control Google Cloud support access to their data through Access Approvals and Access Transparency features.\u003c/p\u003e\n"]]],[],null,["# Document AI security and compliance\n===================================\n\nFollowing are questions and answers applicable in various areas.\n\nSecurity\n--------\n\nTo ensure service security in Document AI, review the following topics.\n\n### How does Google protect and ensure the security of the data I send to Document AI?\n\nRefer to the [Google Cloud Security](/security/solutions) page, which describes the security measures in place for Google Cloud Services.\n\n### What security features does Document AI offer to protect from horizontal attacks that move system to system?\n\nDocument AI supports the following:\n\n- [Data residency](/terms/data-residency)\n- [Deny policy](/iam/docs/deny-overview)\n- [VPC Service Controls (VPC-SC)](/vpc-service-controls/docs/supported-products)\n - [Identity groups and third-party identities in ingress and egress rules](/vpc-service-controls/docs/configure-identity-groups).\n- [Access Transparency](/assured-workloads/access-transparency/docs/supported-services)\n- [Customer-managed encryption keys (CMEK)](/kms/docs/using-other-products)\n - [Using CMEK with Document AI](/document-ai/docs/cmek)\n\nSecurity compliance\n-------------------\n\nThis section describes the questions related to compliance.\n\n### What compliance does Document AI offer?\n\nGoogle Cloud undergoes regular independent third-party audits to verify alignment\nwith security, privacy, and compliance controls. Google Cloud has regular audits\nfor standards such as ISO 27001, ISO 27017, ISO 27018, SOC 2, SOC 3, and PCI DSS.\n\nYou can read more about Google Cloud compliance on the [Compliance resource center](/security/compliance).\n\n### Is Document AI FedRAMP compliant?\n\nDocument AI is [FedRAMP High compliant](/security/compliance/fedramp).\n\n### Is Document AI HIPAA compliant?\n\nDocument AI is [HIPAA compliant](/security/compliance/hipaa-compliance).\n\nSecurity data usage\n-------------------\n\nThis section describes data inquiries.\n\n### Does Google use customer data to improve models?\n\nNo. Google does not use any of your content (such as documents and predictions)\nfor any purpose except to provide you with the Document AI service.\nSee section 17 of the [Google Cloud Terms of Service](https://cloud.google.com/terms/service-terms).\n\nAt Google Cloud, we never use customer data to train our Document AI models.\n\nFor more information, see the [Transparency \\& data protection](/transparency) page.\n\n### In the future, will Google share the document I send to Document AI?\n\nWe won't make the document that you send available to the public or share it with\nanyone else, except as necessary to provide the Document AI service. For\nexample, sometimes we may need to use a third-party vendor to help us provide\nsome aspect of our services, such as storage or transmission of data. Our vendors are\nunder appropriate security and confidentiality contractual obligations. We don't\nshare documents you send with other parties or make them public for any other purpose.\n\n### How long and where will Google store documents I send to Document AI, their results, or other information about requests on its servers? Can I access it?\n\nWhen you send a document to Document AI using a batch request, we must store that\ndocument (encrypted with an ephemeral key, meaning that no human has access to it)\nfor a short period of time in order to perform the analysis and return the results\nto you. For batch operations, the stored document is typically deleted immediately\nafter the processing, with a failsafe [Time to live (TTL)](https://en.wikipedia.org/wiki/Time_to_live)\nof one day. If the batch abends abnormally, the data may persist with a TTL of\nup to one day.\n\n### Synchronous processes\n\nFor online (immediate response) operations, the document data (sent in the request)\nis processed in memory, encrypted in flight, and not persisted to disk. Google\nalso temporarily logs some metadata about your Document AI API requests\n(such as the time the request was received and the size of the request) to\nimprove our service and combat abuse.\n\nFor more information, see [Encryption in transit](/docs/security/encryption-in-transit) and [Regions](/document-ai/docs/regions).\n\n### Does Google claim ownership of the content I send in the request to Document AI\n\nGoogle does not claim any ownership in any of the content (including documents and\npredictions) that you transmit to Document AI. Documents and custom models\nare considered to be (private) customer data. We never use customer data to\nimprove our models. In the rare circumstance where both parties agree to such an\narrangement, an explicit data sharing agreement is crafted.\n\n### What is considered Personally Identifiable Information (PII) that needs to be redacted on documents before being shared with Google?\n\n| **Note:** *Sharing* refers to sending documents to Google for support and professional services purposes. It does not refer to documents processed through Document AI. Such documents are considered private customer data, much like Cloud Storage. No Google employee ever sees them nor extracts their data.\n\nFor document sharing purposes, PII is any information defined as personal\nidentifiable data under applicable laws. Customers must redact the documents prior\nto sharing them with Google, for example when voluntarily done for technical\nsupport purposes to reproduce a problem.\n\nExamples of PII include but are not limited to:\n\n- Date of birth, for example: `2/10/1988`\n- Names of individuals, for example: `Kiran Darko`\n- Personal address, for example: `Evergreen terrace 123`\n- Email address of individuals, for example: `rivelro@test-mail.com`\n- Telephone number of individuals, for example: `636-555-3226`\n- Driver's license number\n- National ID number\n- Employer identification number\n- Bank account information: account IDs, routing numbers, SWIFT IDs\n- Payment card number\n- Gender, for example: `Female, Male, Nonbinary`\n- Ethnicity, for example: `Berber, Italian, Japanese, Latino, Ukrainian`\n- Usernames, ID number of third parties\n- Passport number, for example: `AA1001111`\n- Marital status, for example: `Single, Divorced`\n- Number of allowances or exemptions\n- Dependent names\n- Vehicle identifiers (VIN, license plates, etc.)\n- Any other unique identifying number, characteristic, or code of an individual that could identify an individual consumer, family, or device over time or across services\n\n### Can I resell the Document AI API?\n\nNo, you are not permitted to resell Document AI service. You can still\nintegrate Document AI into applications of independent value.\n\n### How can customers control Google Cloud support access to their documents or data?\n\nAll Document AI parsers support Access Transparency and access approvals. By\ndefault, Google support wouldn't have access to any of customer data or applications.\nIn the situation where access is required from the Google support team, customers\ncan use the [Access Approval](/access-approval/docs/overview) process to authorize\naccess to data or applications. This process starts with the creation of a ticket\nin the Google support portal. The customer then receive a notification (usually\nemail) and an option to authorize or deny access.\n\nGoogle also offers a service called [Access Transparency](/security/products/access-transparency),\nwhich gives customer visibility into all the tasks that Google support performs\nwhile they have access to the system."]]