A
system and method is disclosed for the secure transfer of data by carrier virtual machines between participating physical hosts through a
virtual network (VNET) implemented on one or more internal and / or external networks. The method of the invention can provide additional
security controls, comprising parameters that may include, but are not limited to, time-to-live (TTL),
access control lists (ACLs), usage policies,
directory roles, etc. Additionally, access to one or more of a plurality of carrier
virtual machine payloads by security groups, individual access, subdivided individual access, and
MIME-like
subdivision of a VM-encapsulated
payload may be controlled, thereby providing the carrier VM the ability to carry many secured payloads. In addition, VM packets, a group of packets, a single VM, or subpackets within a VM between network endpoints, or at a predetermined intermediary network point, may be quarantined to realize further security. Individual or combinations of these functionalities on carrier virtual machines, and by extension, application and / or one or more sets of secure data may be implemented.