Skip to main content
compliance · gcp

Vertex AI endpoints created without a customer-managed encryption key

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

Vertex AI endpoints created without `encryptionSpec.kmsKeyName` protect the model files deployed to them with Google default encryption, so you cannot revoke access by disabling a Cloud KMS key. ZopNight flags each such endpoint as a low-severity compliance finding for teams whose policy requires CMEK, with no saving attached.

Signal and threshold

How ZopNight evaluates Vertex AI endpoints created without a customer-managed encryption key.
Field Value
Rule IDsRC-1341
Categorycompliance
Severitylow
Metricnone — pure configuration read
Thresholdno kmsKeyName in encryptionSpec
SourceZopNight
Permissions usedaiplatform.endpoints.list · aiplatform.endpoints.get

What CMEK covers on a prediction endpoint

Every Vertex AI resource is encrypted at rest; the question is whose key. Google’s CMEK page for Vertex AI, now published under the Gemini Enterprise Agent Platform name, lists what a key protects on an endpoint: all model files used for deployments under it, but not in-memory data. It also states the property that makes CMEK worth having: if the key is disabled, the deployed model is automatically undeployed. That is a kill switch you control from Cloud KMS, alongside key rotation schedules and audit logs of key use.

With default encryption none of that exists. Google holds the key, and the only way to cut off the endpoint is IAM or deletion.

Checking which endpoints have a key

Terminal window
gcloud ai endpoints list --region=REGION \
--format="table(name, displayName, encryptionSpec.kmsKeyName)"

An empty last column means the endpoint uses Google default encryption. Endpoints are regional, so run it for each region you deploy in.

How the finding is decided

When ZopNight inventories an endpoint it reads the endpoint’s encryption settings and records whether a Cloud KMS key name is present. The rule fires only on a confirmed “no key” record for a resource of the endpoint type. It does not look at traffic, deployed models or cost.

Endpoints that stay silent

An endpoint with any KMS key set passes, whatever key it is. If the encryption setting was not collected for an endpoint, ZopNight does not assume the worst and raises nothing. Endpoints that serve no traffic are a cost issue handled by GCP Vertex AI Endpoint Idle.

Key control, not savings

The finding carries no saving. The gap is control: no ability to rotate, disable or audit the key protecting deployed model files, which regulated environments often require.

Recreating the endpoint with a key

  1. Create a key ring and key in the endpoint’s region. The key must be in the same region as the resource.

  2. Give the Vertex AI service agent, service-PROJECT_NUMBER@gcp-sa-aiplatform.iam.gserviceaccount.com, the roles/cloudkms.cryptoKeyEncrypterDecrypter role on the key with gcloud kms keys add-iam-policy-binding.

  3. Create a replacement endpoint with the key:

    Terminal window
    gcloud ai endpoints create --region=REGION --display-name=NAME \
    --encryption-kms-key-name=projects/P/locations/REGION/keyRings/KR/cryptoKeys/KEY
  4. Deploy the model to the new endpoint, switch clients to its ID, then undeploy and delete the old one.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·