Skip to main content
Security

Private Domain Control for Qoder CN Enterprise Dedicated Edition

Learn about the design principles, private data network, connectivity policies, and compliance auditing provided by Private Domain Control.

As foundation models continue to evolve, traditional on-premises or VPC-based private-network deployments must balance network and data security with model quality. Capabilities such as model inference, Web Search, the Capability Marketplace, MCP, and cloud Agents commonly require internet access. Any uncontrolled outbound path can create a risk of code or data leakage. Private Domain Control (PDC) for Qoder CN Enterprise Dedicated Edition is designed to address this challenge.

Overview

What is Private Domain Control?

Private Domain Control is a network governance feature for organization administrators using Qoder CN Enterprise Dedicated Edition. It brings network access for model inference, web search, the Capability Marketplace, external tools, and other capabilities under centralized control. Administrators can configure outbound capabilities and the allowed access sources for their enterprise instance, while retaining a complete record of every policy change.

The problem it solves

When enterprises adopt AI coding tools, network governance requirements generally fall into two categories: complete isolation and controlled connectivity. Private Domain Control does not choose for the enterprise. Instead, it helps administrators understand the risks of each controlled capability and configure access as needed.
Choose a connectivity mode based on the required security level

Design principles

  • Switchable: Each controlled capability has an explicit switch. The organization administrator decides whether to allow its internet access.
  • Configurable: In addition to switches, some capabilities support configurable allowlists after they are enabled, such as source rules for IP allowlists.
  • Auditable: Every policy and control change is written to the audit log. Allowed outbound activity is traceable for compliance review.

Capabilities

Private Domain Control is currently available by invitation to customers who subscribe to Enterprise Dedicated Edition. Contact us to request access.
Private Domain Control consists of three areas: private data networking, private-network controls, and compliance auditing.

Private data networking

Private data networking covers critical paths such as model calls, content safety, and version updates. Model and content-safety services connect over PrivateLink instead of the public internet, except for models provided directly by third parties. Client installers and version updates will be distributed through offline media or private sources in a future release. These controls keep relevant traffic off the public internet and within the enterprise-controlled network.

Private-network controls

Private-network controls provide centralized management for fine-grained capabilities. Three policy levels are available: Isolation, Controlled, and Open.
  • Isolation: Keeps data within the trusted boundary with end-to-end isolation, placing AI coding capabilities in a protected environment. Fine-grained controlled capabilities cannot be enabled individually after this level is selected. It is intended for highly regulated scenarios such as core financial systems, government, defense, and confidential workloads.
  • Controlled: Restricts access by default and allows selected capabilities as needed, balancing security, model quality, and efficiency. Administrators can enable or disable controlled capabilities individually. It is intended for most medium and large enterprises that have compliance requirements but still need selected internet capabilities.
  • Open: Enables internet search and external tools by default on top of the controlled foundation, prioritizing model quality and engineering efficiency. Relevant controlled capabilities are enabled by default and cannot be disabled individually. It is intended for fast-moving organizations with high internet dependency and relatively flexible compliance requirements.
Three connectivity policy levels
The following table maps each fine-grained control to the three policy levels.
Fine-grained controlIsolationControlledOpen
Foundation model inferencePrivate connection to Alibaba Cloud Model Studio, except for models provided directly by third partiesPrivate connection to Alibaba Cloud Model Studio, except for models provided directly by third partiesPrivate connection to Alibaba Cloud Model Studio, except for models provided directly by third parties
Inference content safetyPrivate connectionPrivate connectionPrivate connection
Installer downloads and version updates (coming soon)Private networkPrivate networkPrivate network
Web SearchDisabled and cannot be enabledConfigurable switchEnabled and cannot be disabled
Capability MarketplaceDisabled and cannot be enabledConfigurable switchEnabled and cannot be disabled
IDE extension marketplaceDisabled and cannot be enabledConfigurable switchEnabled and cannot be disabled
IP allowlistConfigurable as needed and always enforcedConfigurable as needed and always enforcedConfigurable as needed and always enforced
MCP controlsAll disabledConfigurable as neededAll enabled
VPC email serverEnabled and cannot be disabledConfigurable as neededDisabled and cannot be enabled
Browser Agent (coming soon)Unchanged by policy levelUnchanged by policy levelUnchanged by policy level

Compliance auditing

Private Domain Control provides organization-level auditing. Every Private Domain Control operation is recorded in the platform audit log. Administrators can review trends and details by time and capability type, and export records for internal security reviews and compliance audits.