User Preference: From preferences.json: design_constraints.compliance?
PCI or HIPAA: Neither framework mandates Direct Connect. Bias toward documented private connectivity between sites and AWS (e.g. AWS Direct Connect or Site-to-Site VPN with encryption, monitoring, and change control) — choose with your QSA / BAA / security team; many compliant designs use VPN-only or no hybrid link when all workloads stay in AWS.
FedRAMP: GovCloud and federal boundary requirements dominate; private connectivity is often part of the approved architecture — still confirm with your authorizing official / security team, not this advisor alone.
If compliance includes "ccpa" (CCPA / CPRA) → VPN or Direct Connect both acceptable; prioritize documented data paths, retention controls, and logging for consumer privacy workflows — not a forced Direct Connect gate.
If none of the above: VPN or public-internet paths are commonly acceptable when encrypted and documented.
Feature Parity: Does GCP config require AWS-unsupported features?