dtwo Policy Store

Policies tagged "bigquery"

bigquery · egress

BigQuery: Redact PII in Query Results

Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…

bigqueryredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

bigquery · ingress

Block BigQuery Exfiltration and Cross-Project Writes

Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…

bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa

bigquery · ingress

Block Destructive SQL in BigQuery Queries

Inspects the raw GoogleSQL string carried by BigQuery write-capable query tools and denies any statement in a state-changing class — DML…

bigqueryguard-warehouse-sqlingresssqlreadonlysoc2pci-dsssox

bigquery · ingress

Default-Deny Unaudited BigQuery Tools

Maintains a per-tenant allowlist of audited BigQuery tool-name suffixes and denies any call whose tool name does not end with an allowlisted entry.

bigquerydefault-deny-unknown-toolsallowlistaccess-controlingresssoc2

bigquery · ingress

Fence Regulated BigQuery Datasets by Group

Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.

bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa