Drive-Guard is an automated Security Operations Center (SOC) platform built specifically to detect, monitor, and revoke external collaborator access across Google Workspace and cloud storage drives.
It is built for IT & Security Teams, Digital Agencies, Consultancies, and Freelancers who need to securely manage and offboard access across Google Workspaces without manually auditing thousands of files.
No. Drive-Guard is a completely web-based application. Everything runs directly inside your browser.
Simply click the 'Sign In' button at the top right of this page and authenticate with your Google Workspace account.
Currently, Drive-Guard is optimized for desktop browsers to handle large data visualization and management effectively. A mobile-responsive dashboard is in development.
Yes, you can use Drive-Guard to scan personal @gmail.com accounts, but the primary features are designed for Google Workspace organizational accounts.
Shadow IT refers to unauthorized or unregistered external emails (like a freelancer's personal @gmail.com) that employees share company files with, bypassing official IT oversight.
An orphaned asset is an externally shared file owned by an employee who has since been offboarded. These files often remain accessible to external parties indefinitely if not properly audited.
Yes. Drive-Guard can scan and audit permissions across both 'My Drive' and organizational 'Shared Drives'.
Yes! With our Pro and Enterprise plans, you can delegate access to department heads (e.g., Marketing, Finance) using our Departmental RBAC features.
Yes. Because data is stored locally in your browser storage and never touches our backend, we strictly adhere to GDPR data minimization principles.
Yes. Drive-Guard fully complies with the California Consumer Privacy Act (CCPA) and allows for instant data deletion by simply clearing your browser cache.
Yes. Drive-Guard's zero-knowledge architecture meets the strict compliance requirements of Singapore PDPC, Thailand PDPA, and Malaysia PDPA.
Never. Drive-Guard utilizes the `drive.metadata.readonly` permission scope. We mathematically cannot read the actual contents (text, images, data) of your files.
It means our remote servers literally have zero knowledge of your data. We do not store, process, or transmit your Google Drive files or collaborator lists.
Your data is stored exclusively in your local browser's memory (localStorage and IndexedDB). It never leaves your device.
Because we do not possess your data or API tokens on our backend servers, a breach of our infrastructure cannot result in a breach of your Google Workspace data.
You generate a private API key within your own Google Cloud console. You own the project, meaning you retain the ultimate kill-switch. You can revoke access instantly from your Google Admin console.
Absolutely not. We do not use, sell, or share your Google Workspace data for any AI training or third-party advertising purposes.
Since all data is local, simply clicking 'Sign Out' in the Drive-Guard dashboard will instantly and permanently obliterate all cached session data from your browser.
Absolutely not. Drive-Guard offers a generous Free-Forever tier that requires no payment information upfront.
The Free tier allows you to connect 1 Google Workspace and run unlimited Shadow IT discovery scans. It is perfect for individuals and small teams.
The Free tier does not include advanced enterprise features like Automated TTL Timers, Departmental RBAC delegation, or priority support.
Please visit our Pricing page for the most up-to-date information on our Pro tier, which includes unlimited workspaces and full SOC automation.
Yes. For large organizations requiring custom SLAs, dedicated account managers, and deployment assistance, please contact our sales team.
Yes. You can cancel your Pro or Enterprise subscription at any time directly from your billing dashboard. There are no lock-in contracts.
We offer a 14-day money-back guarantee for all new Pro subscriptions if you are not completely satisfied with the platform.
No. Our pricing is completely transparent. What you see on the Pricing page is exactly what you pay.
Our Pro plan covers a set number of administrator seats. You can easily add additional seats for department heads directly from your billing portal.
Yes! We proudly support 501(c)(3) non-profits and educational institutions with special discounted pricing. Contact our support team to apply.
Drive-Guard requires `drive.metadata.readonly` to scan permissions and `drive.file` to execute revocations. It does not require full drive access.
Use the 'Forward to IT Admin' button in the setup wizard to securely request an Internal Client ID from your IT team.
Drive-Guard can scan any folder or file that your authenticated Google Workspace account has at least 'Viewer' permissions for.
A typical Google Drive containing 10,000 files usually takes less than 45 seconds to fully parse and map into your security dashboard.
Drive-Guard issues an API command directly to Google Workspace to instantly purge the vendor's email address from all shared folders, leaving internal access fully intact.
Because Drive-Guard integrates natively, you can easily go into Google Drive and re-share the folder. We also maintain a local SOC Audit Trail of every revocation.
Currently, Drive-Guard is exclusively built, hyper-optimized, and deeply integrated into the Google Workspace ecosystem.
Drive-Guard is primarily designed to detect and revoke *external* access (Shadow IT). Managing internal domain permissions should be done via Google Admin Groups.
Drive-Guard operates within your Google Cloud Project's native API quotas. Scans run passively in the background without affecting organizational performance.
Our client-side engine includes intelligent backoff and retry logic to ensure large organizational scans never exceed Google's strict API rate limits.
Ensure your browser tab remains active during the scan. If you encounter an error, check your Google Cloud Console for any API quota restrictions.
Ensure that you have correctly added the specific origin URL of Drive-Guard to the 'Authorized JavaScript origins' list in your Google Cloud Console.
This means your Google Workspace has hit its daily API limit. You can request a quota increase directly from your Google Cloud Console.
Since Drive-Guard is client-side, clearing your browser cache (or performing a hard refresh) resolves 99% of loading issues.
You can reach our technical support team at support@drive-guard.io. Pro and Enterprise customers receive priority ticketing.
Phone support and dedicated account managers are exclusively available on our Enterprise plans.
Comprehensive documentation is available inside the app via the 'Help & Playbook' modal. You can access it from the dashboard.
Absolutely! We love user feedback. Please email us your feature requests or drop them in our community Discord.
We push minor updates and bug fixes weekly. Major feature releases are announced monthly via our user newsletter.
Drive-Guard is optimized for the latest versions of Google Chrome, Mozilla Firefox, Apple Safari, and Microsoft Edge.