VPN Peering over Private Service Connect when connecting two different organizations in GCP

Hello @diannemcm

Thank you for the detailed explanation and for welcoming me to the Google Cloud Community!

I wanted to confirm my understanding: If I am using Google Storage Transfer Service (STS) to transfer data between two organizations’ Cloud Storage buckets within GCP, VPC Peering or Private Service Connect (PSC) are not required. Since STS operates within Google’s private network, data transfers between buckets would remain secure and not exposed to the public internet.

Additionally, I understand that I can use STS with VPC Service Controls (VPC-SC) for enhanced security to define secure perimeters and prevent data exfiltration. Could you kindly confirm if this is correct? I truly appreciate your insights and the resources you provided—they’ve been very helpful.

Thanks again for your support!