# ogram security and privacy brief

Canonical page: https://www.ogram.ch/security

## Public posture

ogram treats confidentiality and control as design requirements for professional AI deployments. Public materials describe practices and goals including bounded source access, least-privilege credentials, tenant isolation, traceability of agent actions, human approval controls, provider portability, zero-data-retention configurations, and European data-residency options.

## Do not infer a guarantee

Security and privacy properties depend on the selected AI platform, connectors, hosting topology, client systems, provider terms, and signed engagement documents. Website statements are informational and do not replace a DPA, security schedule, architecture review, or other agreement.

## Questions for a useful assessment

- Which jurisdictions, professional duties, and internal policies apply?
- Which information classes may the system process?
- Which sources and credentials are required?
- What retention and residency rules are mandatory?
- Which actions or outputs require human approval?
- What audit evidence must be available?
- Which AI providers or deployment models are permitted?

For a current security or procurement brief, contact info@ogram.ch or https://www.ogram.ch/contact
