Jump to
VPC Service Controls

VPC Service Controls

Prevent data exfiltration by creating isolation perimeters around cloud services, AI resources, and the networks that connect them.

  • Help protect AI workloads and training data from exfiltration by isolating cloud services and AI resources

  • Ensure sensitive data can only be accessed from authorized networks, identities, and devices using access levels

  • Use native MCP integration to govern autonomous agents within perimeters, even across clouds

  • Control which Google Cloud services and APIs are accessible from a VPC network

Benefits

Mitigate data exfiltration risks across cloud and AI workloads

Enforce perimeters around Google Cloud, storage, and AI resources to mitigate exfiltration from external attackers, compromised service accounts, or unauthorized automated processes.

Keep data private inside the VPC

Private communication between cloud and on-prem VPC networks. Cloud Storage, Bigtable, BigQuery, and AI resources stay private by default.

Support data sovereignty and simplify compliance. 

Enforce granular data boundaries to meet strict regulatory and compliance requirements. VPC Service Controls provides the operational independence needed to run sensitive workloads securely.

Key features

Key features

Centrally enforce security policy across projects and services

Define granular perimeter controls once and apply them across more than a hundred Google Cloud services and projects—without managing policy per resource. Security teams can create, update, and scale perimeters as the environment grows.

Restrict access based on identity, device, and network context

Use access levels to grant or deny access based on user identity, IP range, or device posture—including service accounts used by automated resources and AI agents. Policies apply whether access originates from inside a VPC or over the internet.

Define data boundaries for APIs and storage services

Create perimeters around resources like Cloud Storage, BigQuery, and Bigtable to control exactly how data moves between services, VPCs, and external networks. Prevents both accidental exposure and deliberate exfiltration.

Protect AI workloads and data resources

Apply the same perimeter controls to Gemini Enterprise Agent Platform datasets, training jobs, and model endpoints. Ensure that sensitive training data in BigQuery or Cloud Storage can't be accessed by unauthorized services or exfiltrated through a compromised pipeline.

By using VPC Service Controls, we can achieve a better level of control over where, how, by whom, and when data is allowed to be accessed.

Christian Gorke, VP/Head of Cyber Center of Excellence, Big Data, and Advanced Analytics, Commerzbank

Read the case study

Documentation

Documentation

Best Practice

Supported products and limitations

Explore a table of products and services that are supported by VPC Service Controls, as well as a list of known limitations with certain services and interfaces.

Best Practice

Service perimeter details and configuration

Learn all about service perimeters, including how they function, how to configure them, and the difference between enforced and dry run perimeters.

Best Practice

Creating a service perimeter

Find out how to create a service perimeter, including how to include projects and protect services.

Best Practice

Setting up private connectivity to Google APIs and services

See how to use VPC Service Controls to control access to Google APIs and services from hosts that use private IP addresses.

Best Practice

Setting up Artifact Registry for GKE private clusters

Learn how to configure DNS entries for using Artifact Registry with a Google Kubernetes Engine private cluster and VPC Service Controls.

Best Practice

Cloud IAM roles for administering VPC Service Controls

Uncover the Cloud Identity and Access Management (Cloud IAM) roles required to configure VPC Service Controls.

Google Cloud Basics

Concepts

Find an overview of VPC Service Controls along with a detailed guide covering everything from service perimeter configuration to audit logging.

Architecture

Transferring data from Amazon S3 to Cloud Storage

Learn how to harden data transfers from Amazon Simple Storage Service to Cloud Storage using Storage Transfer Service with a VPC Service Controls perimeter.

Architecture

Threat and data-theft prevention policies with VM-Series

Use a next generation firewall to reduce your threat footprint by centralizing management and extending security policies and controls to users, apps, and devices.

Not seeing what you’re looking for?

Use cases

Use cases

Use case
Secure your AI data sources and models

Establish perimeters around sensitive data in BigQuery and Cloud Storage, and securely connect to Gemini Enterprise Agent Platform. Agent Identity support lets you enforce VPC-SC rules on AI agents to prevent proprietary data leaks. Native Model Context Protocol (MCP) integration ensures cross-cloud agents remain governed by existing perimeters.


Use case
Mitigate data exfiltration and data loss

Address threats including data theft, accidental exposure, and excessive access to data stored in Google Cloud services, whether the risk comes from a malicious insider, a misconfigured service, or a compromised AI pipeline. VPC Service Controls lets you tightly control what identities and services can access what data, reducing both intentional and unintentional losses.


Use case
Isolate environments by trust level

Segment your cloud environment and enforce boundaries based on service, identity, and network context. Extend those boundaries to include managed Google Cloud services, and control egress and ingress of data, including between AI workloads operating at different trust levels.


Use case
Enforce zero-trust access across data resources

Built on Google's zero-trust heritage, VPC Service Controls enforces deny-by-default access based on authorized IPs, identity, device posture, and client context using access levels to verify device posture. Covers services across your resources - including GKE, BigQuery, and Gemini Enterprise Agent Platform - keeping your data processing resources private end to end.

Generate a solution
What problem are you trying to solve?
What you'll get:
Step-by-step guide
Reference architecture
Available pre-built solutions
This service was built with Gemini Enterprise Agent Platform. You must be 18 or older to use it. Do not enter sensitive, confidential, or personal info.

All features

All features

Coverage of services

VPC SC offers broad coverage across  internet-to-service, service-to-service, and VPC-to-service access controls.



Rich security logging

Maintain an ongoing log of access denials to identify potential threats. Flow logs capture near real-time visibility into IP traffic across Compute Engine network interfaces. Seamlessly ingest security telemetry into Google SecOps with updated architectural guidance and expanded ingress/egress rules designed for continuous SIEM and Security Command Center monitoring.

Support for hybrid environments

Configure private communication to cloud resources from VPC networks spanning cloud and on-premises deployments using Private Google Access. Easily extend your perimeter into private, on-premises address spaces using private IP access levels to apply granular subnetwork controls.

Secure communication

Control which resources can communicate across or outside service perimeters,  preventing unauthorized data movement between services.

Context-aware access

Grant or deny access to Google Cloud services based on attributes like IP address, user identity, and device posture.

Perimeter security for managed Google Cloud services

Configure service perimeters to control communications between Compute Engine virtual machines and managed Google Cloud resources. Service perimeters allow free communication within the zone and block all service communication outside the perimeter.

Pricing

Pricing

There is no separate charge for using VPC Service Controls.

Take the next step

Start building on Google Cloud with $300 in free credits and 20+ always free products.

Security
Google Cloud