# nogram security and privacy brief

Canonical page: https://nogram.ch/security

## Public posture

nogram treats confidentiality and control as design requirements for professional AI deployments. Public materials describe practices and goals including bounded source access, least-privilege credentials, tenant isolation, traceability of agent actions, human approval controls, provider portability, zero-data-retention configurations, and European data-residency options.

## Do not infer a guarantee

Security and privacy properties depend on the selected AI platform, connectors, hosting topology, client systems, provider terms, and signed engagement documents. Website statements are informational and do not replace a DPA, security schedule, architecture review, or other agreement.

## Questions for a useful assessment

- Which jurisdictions, professional duties, and internal policies apply?
- Which information classes may the system process?
- Which sources and credentials are required?
- What retention and residency rules are mandatory?
- Which actions or outputs require human approval?
- What audit evidence must be available?
- Which AI providers or deployment models are permitted?

For a current security or procurement brief, contact info@nogram.ch or https://nogram.ch/contact
