Learn about the design principles, private data network, connectivity policies, and compliance auditing provided by Private Domain Control.
As foundation models continue to evolve, traditional on-premises or VPC-based private-network deployments must balance network and data security with model quality. Capabilities such as model inference, Web Search, the Capability Marketplace, MCP, and cloud Agents commonly require internet access. Any uncontrolled outbound path can create a risk of code or data leakage. Private Domain Control (PDC) for Qoder CN Enterprise Dedicated Edition is designed to address this challenge.
Private Domain Control is a network governance feature for organization administrators using Qoder CN Enterprise Dedicated Edition. It brings network access for model inference, web search, the Capability Marketplace, external tools, and other capabilities under centralized control. Administrators can configure outbound capabilities and the allowed access sources for their enterprise instance, while retaining a complete record of every policy change.
When enterprises adopt AI coding tools, network governance requirements generally fall into two categories: complete isolation and controlled connectivity. Private Domain Control does not choose for the enterprise. Instead, it helps administrators understand the risks of each controlled capability and configure access as needed.
Private Domain Control consists of three areas: private data networking, private-network controls, and compliance auditing.
Private data networking covers critical paths such as model calls, content safety, and version updates. Model and content-safety services connect over PrivateLink instead of the public internet, except for models provided directly by third parties. Client installers and version updates will be distributed through offline media or private sources in a future release. These controls keep relevant traffic off the public internet and within the enterprise-controlled network.
Private-network controls provide centralized management for fine-grained capabilities. Three policy levels are available: Isolation, Controlled, and Open.
The following table maps each fine-grained control to the three policy levels.
Private Domain Control provides organization-level auditing. Every Private Domain Control operation is recorded in the platform audit log. Administrators can review trends and details by time and capability type, and export records for internal security reviews and compliance audits.
Overview
What is Private Domain Control?
Private Domain Control is a network governance feature for organization administrators using Qoder CN Enterprise Dedicated Edition. It brings network access for model inference, web search, the Capability Marketplace, external tools, and other capabilities under centralized control. Administrators can configure outbound capabilities and the allowed access sources for their enterprise instance, while retaining a complete record of every policy change.
The problem it solves
When enterprises adopt AI coding tools, network governance requirements generally fall into two categories: complete isolation and controlled connectivity. Private Domain Control does not choose for the enterprise. Instead, it helps administrators understand the risks of each controlled capability and configure access as needed.

Design principles
- Switchable: Each controlled capability has an explicit switch. The organization administrator decides whether to allow its internet access.
- Configurable: In addition to switches, some capabilities support configurable allowlists after they are enabled, such as source rules for IP allowlists.
- Auditable: Every policy and control change is written to the audit log. Allowed outbound activity is traceable for compliance review.
Capabilities
Private Domain Control is currently available by invitation to customers who subscribe to Enterprise Dedicated Edition. Contact us to request access.
Private data networking
Private data networking covers critical paths such as model calls, content safety, and version updates. Model and content-safety services connect over PrivateLink instead of the public internet, except for models provided directly by third parties. Client installers and version updates will be distributed through offline media or private sources in a future release. These controls keep relevant traffic off the public internet and within the enterprise-controlled network.
Private-network controls
Private-network controls provide centralized management for fine-grained capabilities. Three policy levels are available: Isolation, Controlled, and Open.
- Isolation: Keeps data within the trusted boundary with end-to-end isolation, placing AI coding capabilities in a protected environment. Fine-grained controlled capabilities cannot be enabled individually after this level is selected. It is intended for highly regulated scenarios such as core financial systems, government, defense, and confidential workloads.
- Controlled: Restricts access by default and allows selected capabilities as needed, balancing security, model quality, and efficiency. Administrators can enable or disable controlled capabilities individually. It is intended for most medium and large enterprises that have compliance requirements but still need selected internet capabilities.
- Open: Enables internet search and external tools by default on top of the controlled foundation, prioritizing model quality and engineering efficiency. Relevant controlled capabilities are enabled by default and cannot be disabled individually. It is intended for fast-moving organizations with high internet dependency and relatively flexible compliance requirements.

| Fine-grained control | Isolation | Controlled | Open |
|---|---|---|---|
| Foundation model inference | Private connection to Alibaba Cloud Model Studio, except for models provided directly by third parties | Private connection to Alibaba Cloud Model Studio, except for models provided directly by third parties | Private connection to Alibaba Cloud Model Studio, except for models provided directly by third parties |
| Inference content safety | Private connection | Private connection | Private connection |
| Installer downloads and version updates (coming soon) | Private network | Private network | Private network |
| Web Search | Disabled and cannot be enabled | Configurable switch | Enabled and cannot be disabled |
| Capability Marketplace | Disabled and cannot be enabled | Configurable switch | Enabled and cannot be disabled |
| IDE extension marketplace | Disabled and cannot be enabled | Configurable switch | Enabled and cannot be disabled |
| IP allowlist | Configurable as needed and always enforced | Configurable as needed and always enforced | Configurable as needed and always enforced |
| MCP controls | All disabled | Configurable as needed | All enabled |
| VPC email server | Enabled and cannot be disabled | Configurable as needed | Disabled and cannot be enabled |
| Browser Agent (coming soon) | Unchanged by policy level | Unchanged by policy level | Unchanged by policy level |

