Skip to main content
Cloud / Google Cloud / Products / Shielded VMs - Secure Compute Instances

Shielded VMs - Secure Compute Instances

Shielded VM provides hardened VM instances with Secure Boot, integrity monitoring, and vTPM for enhanced security on Google Cloud.

Compute
Pricing Model Typically no separate additional cost, part of Compute Engine (check current pricing)
Availability Global with EU regions
Data Sovereignty EU regions available
Reliability SLA as published by the provider (see Compute Engine SLA) SLA

Shielded VM provides hardened Compute Engine instances with Secure Boot, vTPM, and integrity monitoring for enhanced security and verifiable boot integrity.

What is Google Cloud Shielded VM?

Shielded VM is a security feature for Compute Engine instances that provides verifiable integrity, so users can be confident their VMs have not been compromised by boot- or kernel-level malware or rootkits. The feature uses three main technologies: Secure Boot verifies the integrity of the bootloader and kernel, a virtual Trusted Platform Module (vTPM) provides secure key storage and Measured Boot, and integrity monitoring detects changes to the boot process.

These features prevent malware from loading during the boot process and enable verification that VMs are running in a trusted state. Shielded VM uses UEFI firmware for a modern, secure boot process. The vTPM stores measurements of each boot component that can be used for attestation.

Shielded VM can be enabled for compatible VM instances. Most Google-provided OS images support the feature. Custom images must be UEFI-compatible. Integrity events can be logged and used for alerts.

Typical Use Cases

Security-Critical Production Workloads

A financial services company enables Shielded VM for production systems. Secure Boot prevents loading tampered bootloaders, and integrity monitoring helps detect boot anomalies early.

Compliance for Regulated Industries

A healthcare company uses Shielded VM for workloads with high compliance requirements. Boot integrity verification supports audit documentation. The vTPM enables secure key storage for encryption applications.

Protection Against Persistent Malware

An e-commerce company protects web servers with Shielded VM. Rootkits that would infect the boot process are blocked by Secure Boot. On suspected compromise, the vTPM provides data for forensic analysis.

Secure Development Environments

A technology company enables Shielded VM for developer workstations in the cloud. Secure Boot prevents loading unsigned drivers, and integrity monitoring detects unauthorized changes.

Benefits

  • Verifiable boot integrity without additional infrastructure
  • Protection against rootkits and bootkits at the firmware level
  • Supports compliance evidence for regulated industries
  • Simple activation for compatible VM images

Integration with innFactory

As a certified Google Cloud Partner, innFactory supports you with Shielded VM: activation, image compatibility, integrity monitoring setup, and compliance implementation.

Contact us for a consultation on Shielded VM and Google Cloud security.

Available Tiers & Options

Typical Use Cases

Security-critical workloads
Compliance requirements
Boot integrity verification
Rootkit protection
Regulated industries

Technical Specifications

API Compute Engine API
Boot verification UEFI firmware with Secure Boot
Integration Native Compute Engine integration
Security Secure Boot, vTPM, Integrity Monitoring

Frequently Asked Questions

What is Google Cloud Shielded VM?

Shielded VM is a security feature for Compute Engine instances that provides verifiable integrity. Using Secure Boot, a virtual Trusted Platform Module (vTPM), and integrity monitoring, it helps ensure VMs have not been compromised by boot- or kernel-level malware or rootkits.

Does Shielded VM cost extra?

Shielded VM is built into Compute Engine as a security feature, and typically no separate additional cost applies. For binding pricing details, check the current Compute Engine pricing page.

What is Secure Boot?

Secure Boot verifies that the bootloader and OS kernel are digitally signed and trusted. This prevents loading malware or tampered bootloaders at VM startup.

What does the vTPM do?

The virtual Trusted Platform Module (vTPM) stores cryptographic keys and measurements of the boot process. It enables Measured Boot, attestation, and secure key storage, for example for disk encryption.

How does integrity monitoring work?

Integrity monitoring compares boot measurements against an expected baseline. Deviations are logged, allowing alerts to be configured for potential boot compromise.

Which images support Shielded VM?

Most Google-provided images support Shielded VM. Custom images must be UEFI-compatible for the feature to be enabled.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Comparable Products from Other Clouds

As a multi-cloud partner, we help you choose the right platform for your specific requirements.

Ready to start with Shielded VMs - Secure Compute Instances?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation