← All docs
GCP
Compute Engine, Persistent Disks, VPC networks, Firewall rules, Storage buckets, and Cloud SQL.
What's collected
Compute Engine instances, Persistent Disks, VPC networks, Firewall rules, Cloud Storage buckets, and Cloud SQL instances — plus Cloud Monitoring CPU metrics for rightsizing.
Security & reliability rules
Firewall rules open to the internet, public storage buckets, Cloud SQL instances with a public IP or no SSL requirement, and preemptible instances running in production.
No downloadable key, ever
The platform authenticates by impersonating a Service Account you create — the same trust model as AWS AssumeRole — so no key ever exists for it to leak in the first place.