Model Armor is a Google Cloud service that helps enhance the security and safety of AI applications. It proactively screens Model Context Protocol (MCP) tool calls and responses to help mitigate risks and support responsible AI practices. Whether you deploy AI in Google Cloud or on other cloud providers, Model Armor helps you protect against malicious input, verify content safety, and identify sensitive data. Use Model Armor to consistently apply safety policies and support compliance across your AI landscape.
Products with Model Armor support
The following table lists the Google and Google Cloud MCP servers that support Model Armor and the behavior and limitations of their integrations.
| Product | Behavior and limitations |
|---|---|
| AlloyDB for PostgreSQL | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| BigQuery | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| BigQuery Data Transfer Service | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| BigQuery Migration Service | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Bigtable | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Cloud Run | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Customer Experience Agent Studio | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Cloud SQL | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Cloud Logging | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Cloud Monitoring | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Cloud Trace | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Compute Engine | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Datastream | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Database Migration Service | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Error Reporting | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Firestore | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| GKE | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Google Security Operations | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Managed Service for Apache Kafka | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Memorystore | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Pub/Sub | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Resource Manager | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Spanner | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Vertex AI | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |
| Vertex AI Search | When Model Armor is enabled and you use the MCP server in a jurisdiction that Model Armor doesn't support, the MCP call is sent to a supported jurisdiction. For more information, see Model Armor locations. |