Jump to
VPC Service Controls

VPC Service Controls

Prevent data exfiltration by creating isolation perimeters around cloud services, AI resources, and the networks that connect them.

  • Help protect AI workloads and training data from exfiltration by isolating cloud services and AI resources

  • Ensure sensitive data can only be accessed from authorized networks, identities, and devices using access levels

  • Use native MCP integration to govern autonomous agents within perimeters, even across clouds

  • Control which Google Cloud services and APIs are accessible from a VPC network

Benefits

Mitigate data exfiltration risks across cloud and AI workloads

Enforce perimeters around Google Cloud, storage, and AI resources to mitigate exfiltration from external attackers, compromised service accounts, or unauthorized automated processes.

Keep data private inside the VPC

Private communication between cloud and on-prem VPC networks. Cloud Storage, Bigtable, BigQuery, and AI resources stay private by default.

Support data sovereignty and simplify compliance. 

Enforce granular data boundaries to meet strict regulatory and compliance requirements. VPC Service Controls provides the operational independence needed to run sensitive workloads securely.

Key features

Key features

Centrally enforce security policy across projects and services

Define granular perimeter controls once and apply them across more than a hundred Google Cloud services and projects—without managing policy per resource. Security teams can create, update, and scale perimeters as the environment grows.

Restrict access based on identity, device, and network context

Use access levels to grant or deny access based on user identity, IP range, or device posture—including service accounts used by automated resources and AI agents. Policies apply whether access originates from inside a VPC or over the internet.

Define data boundaries for APIs and storage services

Create perimeters around resources like Cloud Storage, BigQuery, and Bigtable to control exactly how data moves between services, VPCs, and external networks. Prevents both accidental exposure and deliberate exfiltration.

Protect AI workloads and data resources

Apply the same perimeter controls to Gemini Enterprise Agent Platform datasets, training jobs, and model endpoints. Ensure that sensitive training data in BigQuery or Cloud Storage can't be accessed by unauthorized services or exfiltrated through a compromised pipeline.

By using VPC Service Controls, we can achieve a better level of control over where, how, by whom, and when data is allowed to be accessed.

Christian Gorke, VP/Head of Cyber Center of Excellence, Big Data, and Advanced Analytics, Commerzbank

Read the case study

Documentation

Documentation

Best Practice

Supported products and limitations

Explore a table of products and services that are supported by VPC Service Controls, as well as a list of known limitations with certain services and interfaces.

Best Practice

Service perimeter details and configuration

Learn all about service perimeters, including how they function, how to configure them, and the difference between enforced and dry run perimeters.

Best Practice

Creating a service perimeter

Find out how to create a service perimeter, including how to include projects and protect services.

Best Practice

Setting up private connectivity to Google APIs and services

See how to use VPC Service Controls to control access to Google APIs and services from hosts that use private IP addresses.

Best Practice

Setting up Artifact Registry for GKE private clusters

Learn how to configure DNS entries for using Artifact Registry with a Google Kubernetes Engine private cluster and VPC Service Controls.

Best Practice

Cloud IAM roles for administering VPC Service Controls

Uncover the Cloud Identity and Access Management (Cloud IAM) roles required to configure VPC Service Controls.

Google Cloud Basics

Concepts

Find an overview of VPC Service Controls along with a detailed guide covering everything from service perimeter configuration to audit logging.

Architecture

Transferring data from Amazon S3 to Cloud Storage

Learn how to harden data transfers from Amazon Simple Storage Service to Cloud Storage using Storage Transfer Service with a VPC Service Controls perimeter.

Architecture

Threat and data-theft prevention policies with VM-Series