Prevent data exfiltration by creating isolation perimeters around cloud services, AI resources, and the networks that connect them.
Help protect AI workloads and training data from exfiltration by isolating cloud services and AI resources
Ensure sensitive data can only be accessed from authorized networks, identities, and devices using access levels
Use native MCP integration to govern autonomous agents within perimeters, even across clouds
Control which Google Cloud services and APIs are accessible from a VPC network
Benefits
Mitigate data exfiltration risks across cloud and AI workloads
Enforce perimeters around Google Cloud, storage, and AI resources to mitigate exfiltration from external attackers, compromised service accounts, or unauthorized automated processes.
Keep data private inside the VPC
Private communication between cloud and on-prem VPC networks. Cloud Storage, Bigtable, BigQuery, and AI resources stay private by default.
Support data sovereignty and simplify compliance.
Enforce granular data boundaries to meet strict regulatory and compliance requirements. VPC Service Controls provides the operational independence needed to run sensitive workloads securely.
Key features
Define granular perimeter controls once and apply them across more than a hundred Google Cloud services and projects—without managing policy per resource. Security teams can create, update, and scale perimeters as the environment grows.
Use access levels to grant or deny access based on user identity, IP range, or device posture—including service accounts used by automated resources and AI agents. Policies apply whether access originates from inside a VPC or over the internet.
Create perimeters around resources like Cloud Storage, BigQuery, and Bigtable to control exactly how data moves between services, VPCs, and external networks. Prevents both accidental exposure and deliberate exfiltration.
Apply the same perimeter controls to Gemini Enterprise Agent Platform datasets, training jobs, and model endpoints. Ensure that sensitive training data in BigQuery or Cloud Storage can't be accessed by unauthorized services or exfiltrated through a compromised pipeline.
By using VPC Service Controls, we can achieve a better level of control over where, how, by whom, and when data is allowed to be accessed.
Christian Gorke, VP/Head of Cyber Center of Excellence, Big Data, and Advanced Analytics, Commerzbank
What's new
Sign up for Google Cloud newsletters to receive product updates, event information, special offers, and more.
Documentation