Google Workspace's own-key encryption now sets up in a few clicks, so even Google can't read the locked files
By Brett Gavaghan, Founder of Adaptd ·
Google added a simple setup option for Workspace client-side encryption on 1 October. It's for Enterprise Plus customers with the Assured Controls add-on.
The short version
- Google Workspace client-side encryption now has a simple setup option that pairs Cloud HSM keys with Google Identity.
- It's live since 1 October 2026 for Enterprise Plus with the Assured Controls or Assured Controls Plus add-on.
- Most small businesses won't need it, but regulated firms should ask whether it now fits their budget.
Client-side encryption has always been the sturdy lock that took a locksmith, a weekend and a lot of documentation to fit. Google says it now takes a few clicks.
What changed in Workspace client-side encryption?
Google Workspace client-side encryption now has a simple setup option that combines Google's Cloud HSM keys with Google Identity, so admins can switch it on in a few clicks. Before this, setup needed a separate key service and an identity provider configured by hand.
Client-side encryption locks content before it reaches Google's servers, so Google can't read it. Google says it covers sensitive email, files, meetings and calendar events. Think safe-deposit box where the bank never gets a copy of the key.
Who can use it, and when?
The simple setup is available now to Google Workspace Enterprise Plus customers with the Assured Controls or Assured Controls Plus add-on. It rolled out to Rapid Release and Scheduled Release domains on 1 October 2026.
Staff don't need to do anything. Organisations that want an outside key service can still use the standard setup.
Should your business use it?
Most small businesses don't need client-side encryption, because Workspace already encrypts data and the edition it needs costs well above a standard plan. It makes sense for firms that handle health, legal or financial records, or that have clients who ask who can read their files.
My advice: if a client contract or regulator has ever asked that question, put it to your Google reseller now that setup is simpler. If nobody has, your time is better spent turning on two-step verification for everyone. Less glamorous, much more useful.
Wondering what this means for your business?
That's exactly what the discovery call is for.