AWS PrivateLink

AWSNetworking

Private service connectivity that exposes services through VPC endpoints — private IPs inside consumer VPCs — without traversing the public internet, NAT gateways, or peering. Foundational for SaaS-on-AWS designs and inter-VPC service meshes

Jurisdictional exposure

Provider HQ
USSeattle, USA

Subject to CLOUD Act, FISA-702, DPF

Region locations
APACCNEEAEUUKUSOther40 regions across 7 jurisdictions
Sovereign option
Yes — 6 sovereign-flagged regions available

Attributes

SLA Uptime
99.99%

Sub-services (3)

Interface Endpoints

ENI-backed endpoints for calling AWS and partner services privately

Gateway Endpoints

Route-table-based endpoints for S3 and DynamoDB with no per-hour charge

Endpoint Services

Publish your own VPC-hosted services to other AWS accounts via PrivateLink

Compliance & Certifications

This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.

Where this runs

40 regions
28 countries
6sovereign
Sovereign regions (6)
  • AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
  • AWS GovCloud (US-East) · AshburnAWS GovCloud (US)
  • AWS GovCloud (US-West) · HillsboroAWS GovCloud (US)
  • AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
  • China (Beijing) · BeijingAWS China (Sinnet)
  • China (Ningxia) · YinchuanAWS China (NWCD)
Commercial regions (34)

Europe (8)

  • Europe (Paris)
  • Europe (Frankfurt)
  • Europe (Ireland)
  • Europe (Milan)
  • Europe (Spain)
  • Europe (Stockholm)
  • Europe (Zurich)
  • Europe (London)

North America (7)

  • Canada West (Calgary)
  • Canada (Central)
  • Mexico (Central)
  • US East (N. Virginia)
  • US West (Oregon)
  • US East (Ohio)
  • US West (N. California)

South America (1)

  • South America (São Paulo)

Asia (11)

  • Asia Pacific (Hong Kong)
  • Asia Pacific (Hyderabad)
  • Asia Pacific (Mumbai)
  • Asia Pacific (Jakarta)
  • Asia Pacific (Osaka)
  • Asia Pacific (Tokyo)
  • Asia Pacific (Malaysia)
  • Asia Pacific (Singapore)
  • Asia Pacific (Seoul)
  • Asia Pacific (Taipei)
  • Asia Pacific (Thailand)

Oceania (3)

  • Asia Pacific (Melbourne)
  • Asia Pacific (Sydney)
  • Asia Pacific (New Zealand)

Middle East (3)

  • Middle East (Bahrain)
  • Israel (Tel Aviv)
  • Middle East (UAE)

Africa (1)

  • Africa (Cape Town)

Tags

Equivalent services on other platforms

Virtual Private CloudAlibaba

Customisable, isolated private network environment on Alibaba Cloud with VSwitches, route tables, Elastic IP, NAT Gateway, VPN Gateway, and Cloud Enterprise Network for global connectivity

Azure Virtual NetworkAzure

Isolated private network infrastructure in Azure with subnets, NSGs, route tables, VNet peering, service endpoints, and hybrid connectivity via VPN or ExpressRoute

Azure Private LinkAzure

Private service connectivity that exposes Azure PaaS services, third-party partner services, and customer services through private endpoints in your VNet, keeping traffic on the Microsoft backbone and eliminating data exfiltration exposure

Civo NetworkingCivo

Per-region private networks, public IPv4 floating IPs, firewall rules, and DNS — all manageable through the same dashboard / API as compute and K8s

Cloud Temple Virtual Private CloudCloud Temple

Automatic, secure private network deployment with software-defined segmentation, route tables, and subnet-level access controls, integrated with the Managed Firewall for perimeter enforcement

Exoscale Private Networks / VPCExoscale

L2 private networks and managed elastic IPs spanning a zone, with security groups and anti-affinity placement

Virtual Private CloudGCP

Software-defined global private network for cloud resources with regional subnets, firewall rules, VPC peering, and private Google access

Private Service ConnectGCP

Private service connectivity that exposes Google APIs, managed services, and third-party SaaS through private endpoints inside your VPC — traffic stays on Google's network, consumer VPCs don't need to overlap with producer VPCs, and endpoints can have custom DNS

Hetzner Private NetworksHetzner

Free private VLANs that span servers, load balancers, and volumes within a network zone, with subnet routing across regions

Virtual Private CloudHuawei

Logically isolated private network for Huawei Cloud resources with subnets, route tables, security groups, NAT gateways, VPN, and Direct Connect for hybrid connectivity

IBM Cloud VPCIBM

Software-defined virtual private cloud with generation-2 infrastructure, subnets, security groups, network ACLs, Transit Gateway integration, dedicated floating IPs, and isolated multi-zone regions across IBM Cloud global infrastructure

IONOS Managed NAT GatewayIONOS

Managed outbound NAT for private-subnet workloads needing internet egress without ingress, with auto-scaling capacity and per-flow source-NAT mapping

IONOS VPN GatewayIONOS

Managed site-to-site IPsec VPN gateway for hybrid connectivity between on-premises networks and IONOS Virtual Datacenters, with high-availability dual-tunnel deployments

Leaf NetworkingLeaf

Private networks, routers, floating IPs, security groups, and load-balancing — OpenStack Neutron-backed. The networking primitives stitching together Leaf VMs and Kubernetes clusters.

Nscale VPC NetworksNscale

Software-defined private networks for Nscale Instances and GPU Clusters, with subnet management, security-group attachment, and inter-region peering

OpenStack NeutronOpenStack

Network-as-a-service component covering virtual networks, subnets, routers, floating IPs, security groups, and pluggable backends for OVS, OVN, Linux bridge, or vendor SDN integrations — equivalent to VPC / Virtual Network / VPC across the hyperscalers

Virtual Cloud NetworkOracle

Software-defined networking for OCI resources with regional VCNs, subnets, security lists, route tables, internet and NAT gateways, and VCN peering

Virtual Private CloudT Cloud

Software-defined isolated networks with custom IPv4/IPv6 ranges, subnets per availability zone, security groups, network ACLs, and route tables; peers with on-prem via Direct Connect or VPN Gateway

Outscale Net (VPC)Outscale

Virtual private network with subnets, route tables, NAT services, internet gateways, and VPC peering. AWS VPC-compatible API. Net is the network primitive every other Outscale IaaS service runs inside.

Outscale VPN ConnectionsOutscale

Managed site-to-site IPsec VPN gateway for hybrid connectivity between on-premises networks and Outscale Nets (VPCs), with high-availability dual-tunnel deployments and IKEv2 support

OVHcloud Public Cloud GatewayOVHcloud

Managed outbound NAT gateway for Public Cloud private networks, providing internet egress for workloads without public IPs and central source-NAT for subnet-wide traffic

OVHcloud Private NetworkOVHcloud

Software-defined private networks (vRack-backed) isolating Public Cloud Instances, Managed Kubernetes nodes, and Managed Databases at the network layer, with subnet management and inter-region connectivity

Scaleway VPCScaleway

Software-defined private networks isolating Instances, Kubernetes Kapsule clusters, and managed databases — with subnet management, VPC peering, and integration with Public Gateway for outbound NAT

Scaleway Public GatewayScaleway

Managed NAT gateway providing internet egress for private-network workloads, plus DHCP and DNS for the private subnet, with optional public-IP and port-forwarding features

Tencent Virtual Private CloudTencent

Isolated multi-region, multi-AZ virtual network with customer-defined subnets, route tables, security groups, network ACLs, VPN gateways, and Peering + Cloud Connect Network for transit between VPCs

UpCloud SDN Private NetworksUpCloud

Software-defined private networks with utility/floating IPs across UpCloud zones for inter-server communication that bypasses the public internet

Pricing

Pricing model:pay-as-you-go