This page describes the security and compliance controls supported by Data Cloud connectors in Gemini Enterprise and explains how to configure organization policies when your project is protected by a VPC Service Controls perimeter.
Supported security and compliance controls
Data Cloud connectors support the following enterprise security and compliance controls in Gemini Enterprise:
- Data residency (DRZ): When you use federated query mode, your customer
data remains where it's already stored and isn't moved. The
connector queries your data in place and returns the results to the agent in
the location of your Gemini Enterprise app. If write actions are
enabled, the agent can also modify data in place within the underlying data
source, subject to the user's Identity and Access Management permissions.
Gemini Enterprise supports data residency in the
usandeumulti-regions. For more information, see Gemini Enterprise locations. - Customer-managed encryption keys (CMEK): When you use federated query mode, your underlying data remains in the connected data source, where you can configure CMEK directly in that service. In Gemini Enterprise, you can use encryption keys managed in Cloud Key Management Service to protect data at rest, including query results returned to the agent and stored in conversations, connector configurations, and end-user credentials. For more information, see Customer-managed encryption keys.
- VPC Service Controls: You can protect your Gemini Enterprise apps and Data Cloud connectors within a VPC Service Controls service perimeter to help mitigate data exfiltration risks. When VPC Service Controls is enabled, you must also allow the Data Cloud connector IDs in your organization policies as described in Allow Data Cloud connectors in organization policies. For general perimeter setup instructions, see Use VPC Service Controls.
Allow Data Cloud connectors in organization policies
If your project is protected by a VPC Service Controls perimeter, or is explicitly
included in the enforcedProjects parameter of an organization policy, Gemini Enterprise
enforces the Google-managed constraints/discoveryengine.managed.allowedDataSources
organization policy constraint. This constraint blocks data store creation
unless the connector's internal identifier is explicitly listed in the
policy's allowedDataSources parameter.
To allow Data Cloud connectors, add the corresponding connector identifier to
the allowedDataSources parameter:
bigquery_mcp: Allows the BigQuery federated data connector.spanner: Allows the Spanner federated data connector.cloudsql: Allows the Cloud SQL federated data connector.alloydb: Allows the AlloyDB for PostgreSQL federated data connector.
For more information about managed constraints and step-by-step instructions for configuring organization policies in the Google Cloud console, see the following resources: