Google Client-Side Encryption for Workspace: A Guide to Your Options with Virtru
Google has made a serious commitment to client-side encryption across Workspace. The architecture is sound: data is encrypted inside the browser before it ever reaches Google's servers, and Google never holds the keys. What that means in practice is that even Google cannot read your sensitive files, emails, or meeting recordings.
But understanding how client-side encryption works — and choosing the right approach for your organization — requires navigating some real complexity. There are two distinct CSE offerings, and they differ significantly in how they're set up, who they're best for, and how they handle day-to-day collaboration.
Virtru has been a Google Workspace CSE key management partner since the program's inception. We currently support more than 6,000 organizations actively collaborating on Workspace, and our software is available in the Google Cloud Marketplace. The purpose of this post is to clearly explain both CSE options, where each fits, and how Virtru supports each one.
What Is Google Client-Side Encryption?
At its core, Google client-side encryption (CSE) means data is encrypted on the user's device — inside the browser — before being transmitted to and stored in Google's cloud. Because the cryptographic keys never touch Google's servers, Google cannot decrypt or view your content.
This is a meaningful architectural distinction from Google's default server-side encryption, where Google manages the keys and therefore retains the ability to access your data. With CSE, you control the keys — and that control is what enables true data sovereignty.
To deploy Google CSE, organizations need to choose an external key management service. Virtru Private Keystore for Google Workspace CSE is one such service — and as of today, the only CSE key management partner offering granular, label-based access control across Shared Drives.
There are two CSE offerings in the Google Workspace portfolio, and they work differently:
- CSE for Google Drive, Docs, Sheets, Slides, Calendar, and Meet — uses symmetric encryption (AES-256) managed by the key service
- CSE for Gmail — two modes: the traditional S/MIME-based approach, and a newer guest-account method (requiring the Assured Controls add-on) that eliminates certificate management entirely
Understanding those differences is essential before choosing your path.
CSE for Google Drive and Workspace Apps
When a user opens or creates a file in Docs, Sheets, or Slides — with Virtru Private Keystore for Google CSE enabled — three things happen:
- The file is encrypted client-side before being uploaded to Google's cloud.
- The encryption keys are stored and managed in the customer's Virtru Private Keystore — not in Google's cloud.
- Only users with appropriate access can retrieve the keys and decrypt the file — Google cannot.

This means your sensitive Workspace data is completely private and indecipherable to both Google and Virtru. It also means protection travels with the data: when files move between Shared Drives, are shared externally, or are accessed from a new device, the encryption follows.
How Virtru Private Keystore Differentiates
All Google CSE key management partners provide the basic architecture above. Virtru goes further in two important ways.
Label-based access control: Virtru integrates with Google Workspace's native labeling and classification system. When a label is applied to a document or Drive folder, Virtru automatically enforces the corresponding access policy — restricting who can decrypt and view that content based on their group membership or organizational unit. This is the data-layer enforcement that Zero Trust frameworks require: granular, context-aware, and persistent.
Here's a video showing how it works.
Shared Drive governance: Virtru is the only CSE key management partner that enforces access controls across all Shared Drives organization-wide. Sensitive content is protected regardless of how users organize or move files within Workspace — which matters enormously in environments where data governance needs to be systematic, not dependent on individual user judgment.
This aligns with the core principle of data-centric security: protection isn't defined by where data lives, but by the policy bound to the data itself.
Google CSE In Real Life: Virtru Customer Examples
SHE BASH, an IT security solutions provider for the federal government and enterprise customers, uses Virtru Private Keystore for Google Workspace CSE to govern CUI data. Here's a video walking through the experience of managing and sharing sensitive information in Google Drive using Virtru and Google.
Solugen, a chemical manufacturing company, uses Virtru Private Keystore for Google Client-Side Encryption — for both Gmail and Google Drive — to govern sensitive CUI data subject to CMMC compliance. Here's a quick video on why they chose Virtru.
CSE for Gmail
Google also extended client-side encryption to Gmail, giving organizations a way to send and receive encrypted email messages where Google itself cannot read the content. CSE for Gmail uses S/MIME encryption — an established standard with specific operational requirements.
For organizations already using CSE for Google Drive, adding CSE for Gmail may feel like a natural extension, but the setup and day-to-day user experience are meaningfully different — and worth evaluating carefully.
Setting Up CSE for Gmail
Implementing CSE for Gmail requires four steps:
1. Choose a key management service. Like CSE for Drive, Gmail CSE requires an external key management partner. Virtru Private Keystore manages hundreds of millions of encryption keys on behalf of Google customers daily, and handles the encryption of S/MIME certificates so that Google cannot access them.
2. Purchase S/MIME certificates for each user. CSE for Gmail requires your organization to obtain S/MIME certificates from a certificate authority and assign unique key pairs to each user. For a 10,000-person organization, that's 10,000 certificates — and your IT team will need to provision and maintain them continuously as staff turns over.
An important nuance here: S/MIME keys are assigned to users, not to individual pieces of data. If a user's key is compromised, all the data that user has shared becomes accessible. This is a meaningful architectural difference from object-level encryption.
3. Upload certificates to Google Cloud. Once certificates are encrypted by the key management partner, they're uploaded to Google Cloud to establish the CSE framework.
4. Train end users on S/MIME key exchange. Before two parties can exchange encrypted messages, they must first send a "signed" email to establish a trusted connection. Users need to understand this process — and follow it correctly with every new external contact. A user cannot send an encrypted email to someone they've never communicated with until that exchange happens.
This structured approach works well in environments with stable, well-defined and repeated external relationships. It's more challenging in organizations with high external collaboration volume or frequent new contact patterns.
CSE for Gmail with Assured Controls: The S/MIME Alternative
Google made a significant update to Gmail CSE in October 2025. Organizations with Google Workspace Enterprise Plus and the Assured Controls add-on can now enable a mode called "Encryption with guest accounts" — which removes the S/MIME certificate requirement entirely.
Here's how it works: instead of exchanging certificates upfront, an encrypted email is sent to any external recipient regardless of their email platform. The recipient gets a notification with a link to a Google-hosted secure portal, verifies their identity with a one-time code sent to their inbox, and reads the message there. No Google account required. No certificate setup on either end.
This is a meaningful improvement in operational simplicity for organizations already invested in the Google Workspace Enterprise stack. A few important limitations to factor in, though:
- Email headers remain unencrypted — subject lines, timestamps, and recipient addresses are visible for routing purposes
- Attachment limit drops to 5 MB (from Gmail's standard 25 MB)
- Several Gmail features are disabled for CSE-encrypted messages: Smart Compose, translation, email summaries, Confidential Mode, and multi-send
- External recipients cannot send encrypted replies — they can respond, but those responses are unencrypted
- Not available on all SKUs — requires Enterprise Plus plus a separate Assured Controls add-on subscription
For organizations that are already on Enterprise Plus and have structured external collaboration patterns, Assured Controls-based CSE is worth serious evaluation. For organizations with dynamic external collaboration, high attachment volumes, or users who depend on Gmail's AI features, those tradeoffs may tip the balance.
Virtru for Gmail: When Google CSE Doesn't Fit
For organizations that need end-to-end encrypted Gmail but want a lighter operational footprint, Virtru for Gmail is a strong, easy-to-use alternative.
Rather than S/MIME certificates or requiring guest accounts, Virtru for Gmail uses object-level encryption — each email and attachment is wrapped in its own distinct layer of protection, with access policies tied to the content itself. This enables organizations to make different access decisions for different pieces of data, based on each recipient's need to know. That's the zero trust principle of "never trust, always verify" applied at the data layer.
From a user perspective: The Virtru plugin surfaces directly in the Gmail Compose window. Users toggle encryption on with a single click. Recipients authenticate with their existing credentials through a secure reader in their browser — no certificates, no key exchange, no new accounts or passwords required.
Virtru for Gmail is particularly well-suited for organizations governed by data privacy regulations like HIPAA, ITAR, CMMC, and CJIS — each of which requires complete privacy for sensitive shared data. It handles dynamic collaboration patterns naturally: a new external contact can receive an encrypted email on the first interaction, without any prior setup.
One real-life example: Recorded Future, a leading cyber threat intelligence company acquired by MasterCard, found thatGmail CSE wasn't the right fit for them — so they opted for Virtru for Gmail, which enables easy-to-use, client-side, end-to-end encryption that meets their teams where and how they work.
Persistent access controls go further than encryption alone:
- Revoke access at any time — If a message reaches the wrong recipient, you can cut off access immediately, even after delivery
- Set expiration dates — Time-limit access to information that's only relevant for a defined period
- Restrict forwarding — Prevent a message from being passed beyond the intended recipient
- Watermark attachments — Apply visible ownership markers to PDFs and files
- Audit all access — Enterprise admins see exactly what data left the organization, when, and who opened it
- Policy portability — protection that travels with the data — is the architectural principle behind all of it.
Virtru Data Protection Gateway: The Server-Side, Domain-Wide Safety Net
Virtru also offers server-side email protection through the Virtru Data Protection Gateway. Rather than relying on user action, the Gateway automatically scans outbound messages against DLP policies and applies TDF-based encryption before email leaves the organization.
This is especially valuable for two specific scenarios: mobile workforces where users may be sending from devices where client-side plugins aren't installed, and line-of-business applications — Salesforce, Zendesk, Looker, and other SMTP-enabled tools — where user-initiated encryption isn't possible at all.
But you can also think of the Virtru Gateway as a "Swiss Army knife" for a wide variety of encryption and decryption flows that can be "daisy-chained" together to fit your needs. Whether it's storing decrypted data for audit logs, or automatically encrypting and protecting inbound or outbound data, the Gateway is versatile for protecting both email and file workflows.
Security should empower your teams, not block them from getting their jobs done. The Gateway extends that philosophy to environments where user-facing tools can't reach, providing a consistent enforcement layer regardless of how or where email originates.
The Google Drive Alternative for Regulated Data: Virtru Collaborate
If your organization stores and shares highly sensitive information subject to CMMC, ITAR, GLBA, CJIS, or other compliance requirements, Virtru Collaborate could be an alternative to Google Drive as a secure enclave for your data. Virtru Collaborate allows you to govern and scope data access with designated, FedRAMP-authorized workspaces for specific projects, where you decide who can access shared information, under what circumstances. Protections follow the data everywhere it moves, giving you confidence and control at every step of a project, contract, or negotiation. Here's how it works.
Choosing the Right Approach
Here's a practical framework for navigating the options:
|
Scenario |
Recommended Approach |
|
High-compliance (CMMC, ITAR, CJIS), dynamic external collaboration |
Virtru for Gmail |
|
Structured external relationships, existing S/MIME infrastructure |
CSE for Gmail + Virtru Private Keystore |
|
Enterprise Plus + Assured Controls, structured external relationships, no S/MIME overhead |
Gmail CSE with guest accounts |
|
Google Drive / Docs / Sheets / Slides protection |
CSE for Workspace + Virtru Private Keystore |
|
Some teams require advanced data security for CUI, CJI, or other regulated information that must be protected and shared. |
Google Drive for standard files + Virtru Collaborate for regulated or highly sensitive files |
|
Server-side coverage, LOB app protection, mobile enforcement |
Virtru Data Protection Gateway |
|
Maximum key sovereignty (all Virtru solutions) |
Add Virtru Private Keystore |
These options aren't mutually exclusive. Many organizations layer them: CSE for Drive combined with Virtru for Gmail, or the Gateway as a server-side enforcement layer under client-side controls. The goal is first-mile to last-mile data protection — securing information from the moment it's created to wherever it ultimately travels.
Getting Started
If you're evaluating CSE for your organization — whether for Google Drive, Gmail, or both — talk to a Virtru expert to understand which architecture fits your compliance requirements and collaboration patterns.
Editorial Team
The editorial team consists of Virtru brand experts, content editors, and vetted field authorities. We ensure quality, accuracy, and integrity through robust editorial oversight, review, and optimization of content from trusted sources, including use of generative AI tools.
View more posts by Editorial TeamSee Virtru In Action
Sign Up for the Virtru Newsletter
Dive Deeper

How to Encrypt Email in Outlook: Your Full Guide

AI Sovereignty isn't Something You Buy. It's Something You Build.
/blog%20-%20cyera%20oasis/cyera-oasis.webp)
The Coin Has Two Sides: What Cyera's Acquisition of Oasis Tells Us About the Future of Security

Virtru Collaborate vs. Box: Secure File Sharing for Businesses of Any Size
/blog%20-%20william%20mcborrough%20recap/cmmc-compass-will-mcborrough.webp)
The $600,000 Problem: What the CMMC Pause Actually Revealed About the Defense Industrial Base
/blog%20-%20three%20stories/three-stories.webp)
Last Week in Critical Infrastructure: Three Stories You Should Read as One
/blog%20-%20cmmc%20on%20hold/CMMC-Pause-CUI-Not.webp)
CMMC Phase II Is Officially on Hold. NIST and DFARS aren't.
/2026%20Newsletter%20Assets/jk-HIO.png)
We Asked Kindervag: Why Are So Many Organizations Still Getting Zero Trust Wrong?
/blog%20-%20ShareFile%20Takedown/26-Competitor-Blog-Blog%20-%20Virtru%20vs%20Sharefile.jpg)
Looking for a ShareFile Alternative? Here's What Regulated Organizations Need to Know.
/blog%20-%20sendsafely%20takedown/26-Competitor-Blog-Blog%20-%20Virtru%20vs%20SendSafely%20(1).jpg)
SendSafely vs. Virtru: Which Secure File Sharing Platform Protects Your Data After Download?
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.