Prevent data exfiltration by creating isolation perimeters around cloud services, AI resources, and the networks that connect them.
Help protect AI workloads and training data from exfiltration by isolating cloud services and AI resources
Ensure sensitive data can only be accessed from authorized networks, identities, and devices using access levels
Use native MCP integration to govern autonomous agents within perimeters, even across clouds
Control which Google Cloud services and APIs are accessible from a VPC network
Benefits
Mitigate data exfiltration risks across cloud and AI workloads
Enforce perimeters around Google Cloud, storage, and AI resources to mitigate exfiltration from external attackers, compromised service accounts, or unauthorized automated processes.
Keep data private inside the VPC
Private communication between cloud and on-prem VPC networks. Cloud Storage, Bigtable, BigQuery, and AI resources stay private by default.
Support data sovereignty and simplify compliance.
Enforce granular data boundaries to meet strict regulatory and compliance requirements. VPC Service Controls provides the operational independence needed to run sensitive workloads securely.
Key features
Define granular perimeter controls once and apply them across more than a hundred Google Cloud services and projects—without managing policy per resource. Security teams can create, update, and scale perimeters as the environment grows.
Use access levels to grant or deny access based on user identity, IP range, or device posture—including service accounts used by automated resources and AI agents. Policies apply whether access originates from inside a VPC or over the internet.
Create perimeters around resources like Cloud Storage, BigQuery, and Bigtable to control exactly how data moves between services, VPCs, and external networks. Prevents both accidental exposure and deliberate exfiltration.
Apply the same perimeter controls to Gemini Enterprise Agent Platform datasets, training jobs, and model endpoints. Ensure that sensitive training data in BigQuery or Cloud Storage can't be accessed by unauthorized services or exfiltrated through a compromised pipeline.
By using VPC Service Controls, we can achieve a better level of control over where, how, by whom, and when data is allowed to be accessed.
Christian Gorke, VP/Head of Cyber Center of Excellence, Big Data, and Advanced Analytics, Commerzbank
What's new
Sign up for Google Cloud newsletters to receive product updates, event information, special offers, and more.
Documentation
Use cases
Establish perimeters around sensitive data in BigQuery and Cloud Storage, and securely connect to Gemini Enterprise Agent Platform. Agent Identity support lets you enforce VPC-SC rules on AI agents to prevent proprietary data leaks. Native Model Context Protocol (MCP) integration ensures cross-cloud agents remain governed by existing perimeters.
Address threats including data theft, accidental exposure, and excessive access to data stored in Google Cloud services, whether the risk comes from a malicious insider, a misconfigured service, or a compromised AI pipeline. VPC Service Controls lets you tightly control what identities and services can access what data, reducing both intentional and unintentional losses.
Segment your cloud environment and enforce boundaries based on service, identity, and network context. Extend those boundaries to include managed Google Cloud services, and control egress and ingress of data, including between AI workloads operating at different trust levels.
Built on Google's zero-trust heritage, VPC Service Controls enforces deny-by-default access based on authorized IPs, identity, device posture, and client context using access levels to verify device posture. Covers services across your resources - including GKE, BigQuery, and Gemini Enterprise Agent Platform - keeping your data processing resources private end to end.
All features
| Coverage of services | VPC SC offers broad coverage across internet-to-service, service-to-service, and VPC-to-service access controls. |
| Rich security logging | Maintain an ongoing log of access denials to identify potential threats. Flow logs capture near real-time visibility into IP traffic across Compute Engine network interfaces. Seamlessly ingest security telemetry into Google SecOps with updated architectural guidance and expanded ingress/egress rules designed for continuous SIEM and Security Command Center monitoring. |
| Support for hybrid environments | Configure private communication to cloud resources from VPC networks spanning cloud and on-premises deployments using Private Google Access. Easily extend your perimeter into private, on-premises address spaces using private IP access levels to apply granular subnetwork controls. |
| Secure communication | Control which resources can communicate across or outside service perimeters, preventing unauthorized data movement between services. |
| Context-aware access | Grant or deny access to Google Cloud services based on attributes like IP address, user identity, and device posture. |
| Perimeter security for managed Google Cloud services | Configure service perimeters to control communications between Compute Engine virtual machines and managed Google Cloud resources. Service perimeters allow free communication within the zone and block all service communication outside the perimeter. |
Pricing
There is no separate charge for using VPC Service Controls.
Start building on Google Cloud with $300 in free credits and 20+ always free products.