Model Armor supported products

Model Armor is a Google Cloud service that helps enhance the security and safety of AI applications. It proactively screens Model Context Protocol (MCP) tool calls and responses to help mitigate risks and support responsible AI practices. Whether you deploy AI in Google Cloud or on other cloud providers, Model Armor helps you protect against malicious input, verify content safety, and identify sensitive data. Use Model Armor to consistently apply safety policies and support compliance across your AI landscape.

Model Armor is compliant with data residency requirements for at-rest data, but if you have requirements for data residency for in-use data, then different MCP servers might have different behavior as described in the following sections.

MCP calls to Model Armor

Model Armor is compliant with data residency requirements for at-rest data. To comply with data residency needs for in-use data and to ensure reliability, some MCP servers restrict MCP requests to Model Armor within the jurisdiction from which they are sent.

The following sections describe the different types of behavior that are possible:

Cross-jurisdictional routing

MCP servers with cross-jurisdictional routing always send your MCP requests to Model Armor when it is enabled. If Model Armor isn't present in the jurisdiction where the MCP request is sent, then the request is sent to Model Armor in another jurisdiction. These cross-jurisdictional calls might impact your data residency compliance for in-use data.

Data residency compliant routing

MCP servers that comply with data residency requirements for in-use data skip Model Armor screening if Model Armor isn't available in the same jurisdiction as the MCP request. No errors or logs are written when Model Armor is skipped.

If a service only offers MCP endpoints in jurisdictions that are supported by Model Armor, then Model Armor is always called.

For more information, see Data residency and Endpoints.

Jurisdictional routing

MCP servers with jurisdictional routing keep MCP requests to Model Armor within the jurisdiction from which they are sent for reliability reasons but don't meet the requirements of data residency compliance for in-use data. This behavior has two sub-categories:

  • Model Armor is always called: MCP calls are kept within the same jurisdiction and all MCP traffic is sent to Model Armor because Model Armor is present in all available jurisdictions of the MCP endpoint.
  • Model Armor might be skipped: MCP calls are kept within the same jurisdiction and skip Model Armor if Model Armor isn't available in the same jurisdiction as the MCP request. No errors or logs are written when Model Armor is skipped.

Products with Model Armor support

The following table lists the Google and Google Cloud MCP servers that support Model Armor and the behavior and limitations of their integrations when Model Armor is enabled.

Product Model Armor is always called Model Armor might be skipped Details
Agent Registry check Cross-jurisdictional routing. Model Armor is always called when enabled.
AlloyDB for PostgreSQL check Cross-jurisdictional routing. Model Armor is always called when enabled.
Apigee API hub check
Audit Manager check Data residency compliant for in-use data. Model Armor is always called.

Exception: The GenerateAuditScopeReport tool doesn't support scanning with Model Armor

Backup and DR Service check Cross-jurisdictional routing. Model Armor is always called when enabled.
BigQuery check Cross-jurisdictional routing. Model Armor is always called when enabled.
BigQuery Data Transfer Service check Cross-jurisdictional routing. Model Armor is always called when enabled.
BigQuery Migration Service check Cross-jurisdictional routing. Model Armor is always called when enabled.
Bigtable check Cross-jurisdictional routing. Model Armor is always called when enabled.
Cloud Asset Inventory check Cross-jurisdictional routing. Model Armor is always called when enabled.
Cloud Billing check Cross-jurisdictional routing. Model Armor is always called when enabled.
Cloud CLI Execution (Preview) check