Skip to main content
compliance · gcp

Vector Search indexes built without a customer-managed encryption key

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Vector Search indexes created without `--encryption-kms-key-name` keep their vector data files in Cloud Storage, Pub/Sub and internal storage under Google default encryption. ZopNight flags each index lacking a Cloud KMS key, as a low-severity compliance finding, since embeddings derived from private documents usually fall under the same CMEK policy as the documents.

Signal and threshold

How ZopNight evaluates Vector Search indexes built without a customer-managed encryption key.
Field Value
Rule IDsRC-1343
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno kmsKeyName in encryptionSpec
SourceZopNight
Permissions usedaiplatform.indexes.list · aiplatform.indexes.get

What sits inside an index

A Vector Search index is built from embeddings you supply, and embeddings are not anonymous: they are computed from support tickets, contracts, code or medical notes, and can reveal a lot about the source. According to Google’s CMEK documentation, a key on an index protects all data files used for the index, whether in Cloud Storage, Pub/Sub or internal storage.

A customer-managed key lets you rotate on your schedule, audit every use in Cloud KMS logs and disable the key to make the data unreadable. Google default encryption offers none of those levers.

Checking indexes for a key

Terminal window
gcloud ai indexes list --region=REGION \
--format="table(name, displayName, encryptionSpec.kmsKeyName)"

Any index with no value in the key column uses default encryption.

The rule’s single condition

ZopNight records, for every index it inventories, whether the index’s encryption settings carry a Cloud KMS key name. A confirmed “no key” fires the finding. Index size, update method (batch or streaming) and whether it is deployed have no effect.

When the index is not reported

Keyed indexes are silent. Missing encryption data leads to no finding rather than a guessed one. An index that is not deployed anywhere is a separate cost signal, covered by GCP Vertex AI Vector Search Index Not Deployed.

No money involved

The saving is $0. The exposure is regulatory: embeddings of regulated data held without the key control your policy requires.

Rebuilding the index with a key

  1. Create a Cloud KMS key in the index’s region and grant the Vertex AI service agent the roles/cloudkms.cryptoKeyEncrypterDecrypter role on it.

  2. Rebuild the index from its source files with the key:

    Terminal window
    gcloud ai indexes create --region=REGION --display-name=NAME \
    --metadata-file=metadata.json \
    --encryption-kms-key-name=KEY_RESOURCE_NAME
  3. Deploy it to an index endpoint that uses the same key; Google requires the two to match.

  4. Switch queries over, undeploy and delete the old index.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·