Security review for the GCP production environment
Spawned from #175 (closed)
Will need a thorough security review of the GCP environment.
@kathyw @jritchey ideally this should be owned by the security team, do you agree, and if so who should it be.
To avoid surprises, we should probably start this as soon as possible.
Edited by Andrew Newdigate