Secure Data Cloud connectors

This page describes the security and compliance controls supported by Data Cloud connectors in Gemini Enterprise and explains how to configure organization policies when your project is protected by a VPC Service Controls perimeter.

Supported security and compliance controls

Data Cloud connectors support the following enterprise security and compliance controls in Gemini Enterprise:

  • Data residency (DRZ): When you use federated query mode, your customer data remains where it's already stored and isn't moved. The connector queries your data in place and returns the results to the agent in the location of your Gemini Enterprise app. If write actions are enabled, the agent can also modify data in place within the underlying data source, subject to the user's Identity and Access Management permissions. Gemini Enterprise supports data residency in the us and eu multi-regions. For more information, see Gemini Enterprise locations.
  • Customer-managed encryption keys (CMEK): When you use federated query mode, your underlying data remains in the connected data source, where you can configure CMEK directly in that service. In Gemini Enterprise, you can use encryption keys managed in Cloud Key Management Service to protect data at rest, including query results returned to the agent and stored in conversations, connector configurations, and end-user credentials. For more information, see Customer-managed encryption keys.
  • VPC Service Controls: You can protect your Gemini Enterprise apps and Data Cloud connectors within a VPC Service Controls service perimeter to help mitigate data exfiltration risks. When VPC Service Controls is enabled, you must also allow the Data Cloud connector IDs in your organization policies as described in Allow Data Cloud connectors in organization policies. For general perimeter setup instructions, see Use VPC Service Controls.

Allow Data Cloud connectors in organization policies

If your project is protected by a VPC Service Controls perimeter, or is explicitly included in the enforcedProjects parameter of an organization policy, Gemini Enterprise enforces the Google-managed constraints/discoveryengine.managed.allowedDataSources organization policy constraint. This constraint blocks data store creation unless the connector's internal identifier is explicitly listed in the policy's allowedDataSources parameter.

To allow Data Cloud connectors, add the corresponding connector identifier to the allowedDataSources parameter:

  • bigquery_mcp: Allows the BigQuery federated data connector.
  • spanner: Allows the Spanner federated data connector.
  • cloudsql: Allows the Cloud SQL federated data connector.
  • alloydb: Allows the AlloyDB for PostgreSQL federated data connector.

For more information about managed constraints and step-by-step instructions for configuring organization policies in the Google Cloud console, see the following resources: