Skip to main content
This document explains how to connect to a W&B Dedicated Cloud instance over a cloud provider’s secure private network, so that traffic between your environment and Weights & Biases avoids the public internet. It’s intended for cloud and security administrators who manage Dedicated Cloud instances and want to harden network access for AI workloads and user traffic. You can connect to your Dedicated Cloud instance over the cloud provider’s secure private network. This applies to access from your AI workloads to the W&B APIs and optionally from your user browsers to the W&B app UI. When you use private connectivity, the relevant requests and responses don’t transit through the public network or internet. This reduces exposure to the public internet and helps satisfy network isolation requirements for sensitive workloads.
Secure private connectivity is offered as an advanced security option with Dedicated Cloud.
Secure private connectivity is available on Dedicated Cloud instances on AWS, Google Cloud, and Azure: After enabling private connectivity, Weights & Biases creates a private endpoint service for your instance and provides its DNS URI. Create private endpoints in your cloud accounts to route AI workload traffic from your VPC or VNet to that service. To route browser traffic privately as well, configure DNS routing from your corporate network to those endpoints. Browser requests must resolve to the private endpoint instead of the public endpoint.
To use this feature, contact Support.
You can use secure private connectivity with IP allowlisting to combine network isolation with location-based access controls. If you combine the two, Weights & Biases recommends that you use secure private connectivity for all traffic from your AI workloads and for browser traffic from your users where possible, and use IP allowlisting for instance administration from privileged locations.
Last modified on September 30, 2026