Model Armor is a Google Cloud service that helps enhance the security and safety of AI applications. It proactively screens Model Context Protocol (MCP) tool calls and responses to help mitigate risks and support responsible AI practices. Whether you deploy AI in Google Cloud or on other cloud providers, Model Armor helps you protect against malicious input, verify content safety, and identify sensitive data. Use Model Armor to consistently apply safety policies and support compliance across your AI landscape.
Model Armor is compliant with data residency requirements for at-rest data, but if you have requirements for data residency for in-use data, then different MCP servers might have different behavior as described in the following sections.
MCP calls to Model Armor
Model Armor is compliant with data residency requirements for at-rest data. To comply with data residency needs for in-use data and to ensure reliability, some MCP servers restrict MCP requests to Model Armor within the jurisdiction from which they are sent.
The following sections describe the different types of behavior that are possible:
Cross-jurisdictional routing
MCP servers with cross-jurisdictional routing always send your MCP requests to Model Armor when it is enabled. If Model Armor isn't present in the jurisdiction where the MCP request is sent, then the request is sent to Model Armor in another jurisdiction. These cross-jurisdictional calls might impact your data residency compliance for in-use data.
Data residency compliant routing
MCP servers that comply with data residency requirements for in-use data skip Model Armor screening if Model Armor isn't available in the same jurisdiction as the MCP request. No errors or logs are written when Model Armor is skipped.
If a service only offers MCP endpoints in jurisdictions that are supported by Model Armor, then Model Armor is always called.
For more information, see Data residency and Endpoints.
Jurisdictional routing
MCP servers with jurisdictional routing keep MCP requests to Model Armor within the jurisdiction from which they are sent for reliability reasons but don't meet the requirements of data residency compliance for in-use data. This behavior has two sub-categories:
- Model Armor is always called: MCP calls are kept within the same jurisdiction and all MCP traffic is sent to Model Armor because Model Armor is present in all available jurisdictions of the MCP endpoint.
- Model Armor might be skipped: MCP calls are kept within the same jurisdiction and skip Model Armor if Model Armor isn't available in the same jurisdiction as the MCP request. No errors or logs are written when Model Armor is skipped.
Products with Model Armor support
The following table lists the Google and Google Cloud MCP servers that support Model Armor and the behavior and limitations of their integrations when Model Armor is enabled.
| Product | Model Armor is always called | Model Armor might be skipped | Details |
|---|---|---|---|
| Agent Registry | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| AlloyDB for PostgreSQL | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Apigee API hub | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | Backup and DR Service | check | Cross-jurisdictional routing. Model Armor is always called when enabled. |
| BigQuery | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| BigQuery Data Transfer Service | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| BigQuery Migration Service | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Bigtable | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Asset Inventory | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud CLI Execution (Preview) | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Filestore | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Run | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Storage | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Support API | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Customer Experience Agent Studio | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud SQL | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Logging | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Monitoring | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Trace | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Compute Engine | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Database Insights MCP server | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Database Center | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Datastream | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Database Migration Service | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Developer Knowledge API | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Error Reporting | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Firestore | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| GKE | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Google Security Operations | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Knowledge Catalog | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Managed Service for Apache Spark | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Managed Service for Apache Kafka | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Managed Service for Apache Airflow | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Memorystore | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Google Cloud NetApp Volumes | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Oracle Database@Google Cloud | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Personalized Service Health | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Pub/Sub | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Recommender | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Cloud Quotas | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Spanner | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Gemini Enterprise Agent Platform | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Agent Search | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Google Drive | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Gmail | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Google Calendar | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| Google Chat | check | Cross-jurisdictional routing. Model Armor is always called when enabled. | |
| People API | check | Cross-jurisdictional routing. Model Armor is always called when enabled. |