VendorScore · Comparison · Data-access posture
Evidence dated 2026-10-06, public docs only, not legal advice.
Short answer
Both can read your documents by default. In the scored configurations, Google Workspace (82/100) has less inherent vendor read access than Microsoft 365 (69/100), because client-side encryption keeps CSE-protected files out of Google's reach, while Microsoft's Customer Key still lets service code decrypt; Double Key Encryption is Microsoft's narrower exception.
Higher score = less inherent vendor read access in the scored configuration, not a more secure product. Each score comes from that vendor's VendorScore page.
| Google Workspace | Microsoft 365 | |
|---|---|---|
| Overall score | 82/100 | 69/100 |
| Scored configuration | Enterprise Plus with Client-side encryption (CSE) for Drive/Docs/Sheets/Slides. | Microsoft 365 enterprise with Purview Customer Key and Customer Lockbox. Double Key Encryption (DKE) is noted as a higher bar for limited content. |
| Key custody option | Client-side encryption (CSE): files are encrypted in the browser and keys are held through your Key Access Control List Service (KACLS). CSE is limited to certain editions and file types. | Purview Customer Key: root keys in Azure Key Vault, but Microsoft 365 service code uses them and Microsoft holds an availability key for recovery. Customer Lockbox gates engineer access. |
| E2EE / CSE scope | CSE-protected Drive/Docs/Sheets/Slides content: Google's docs say its servers can't access the keys and so can't decrypt it. Content without CSE uses Google-managed keys. | Double Key Encryption (DKE) for limited content: you hold a second key Microsoft never has, with major usability and search limits. Other content: the service can decrypt it. |
| AI training default (scored config) | Not used for training by default. Google says Workspace doesn't use customer data to train models without your prior permission or instruction. | Not used for training by default. For Microsoft 365 Copilot, Microsoft says prompts, responses and Microsoft Graph data aren't used to train foundation LLMs. The Microsoft 365 score doesn't cover Copilot. |
| EU residency | Yes, for covered data at rest on supported editions (data regions: EU or US); in-region processing is limited to editions such as Enterprise Plus. | Yes, within limits: the EU Data Boundary covers customers with an EU or EFTA sign-up location, with some documented transfers; Multi-Geo customers are out of scope. |
| DPA link | Google Workspace DPA | Microsoft 365 DPA |
Dimension scores (key custody, plaintext access, encryption claims, subprocessors, auditability) stay in the full PDFs.
Get the full 5-dimension PDFs — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
By default, yes: both hold keys and can decrypt content for service operations. With Google Workspace client-side encryption, Google's docs say its servers can't access the keys and therefore can't decrypt CSE data. With Microsoft Customer Key, Microsoft 365 service code still uses your root keys and Microsoft holds an availability key; only Double Key Encryption content is out of Microsoft's reach.
In the scored configurations, Google Workspace scores 82/100 (Enterprise Plus with CSE) and Microsoft 365 69/100 (Customer Key and Customer Lockbox), so Google Workspace has less inherent vendor read access. Without CSE, the report estimates Google Workspace at about 55–60 overall.
Without CSE, Google staff access is restricted and logged rather than impossible, and Access Transparency logs are available on supported services and editions. Microsoft says engineers don't have default access and are granted it under management oversight only when necessary; Customer Lockbox lets you approve or deny those requests.
Google says Workspace doesn't use customer data for training models without your prior permission or instruction. For Microsoft 365 Copilot, Microsoft says prompts, responses and data accessed through Microsoft Graph aren't used to train foundation LLMs.
Google Workspace data regions store covered data at rest in the EU on supported editions; keeping processing in the region is limited to editions such as Enterprise Plus. Microsoft's EU Data Boundary covers Microsoft 365 customers with an EU or EFTA sign-up location, with some documented transfers, and excludes customers who bought Multi-Geo Capabilities.
Every URL cited on this page. Scores, configurations and facts come from the linked VendorScore vendor pages and their reports; nothing here goes beyond them.
This comparison restates the vendor pages for the scored configurations only; default setups usually score lower. A higher score means less inherent vendor read access in that configuration, not a safety rating. VendorScore doesn't certify compliance. Public-docs review only. Not a pen test, not legal advice, not a SOC 2 substitute.