Your account
Survey in your own Google Cloud
The same collector runs once in a Confidential VM in your own Google Cloud project. Google Cloud attests which collector image ran, and the collector token it signs names the exact facts that image sent, so a buyer can check they were not edited. The repository never leaves your project, and Borehole never receives credentials to it.
- Do steps 1 to 3 of a private survey. Sign in, add the Report key, and make a collector token.
- Have a Google Cloud project with billing, and
gcloudsigned in as someone who may enable APIs and create service accounts, secrets and VMs in it. - Make a read-only token for your git host, so the VM can read the repository.
- Download the script and read it. It is short, and it is all of what runs as you.
- Store both tokens as secrets in your project: the collector token and the git host's.
- Run the script, pinned to the collector image by digest. It runs the VM once, prints the report's link, and deletes the VM.
The signature covers what the image read, not whether it was your real codebase. Run it in your own cloud says what it proves and what it does not.