
Data security
Ogment is built for firms that owe their clients confidentiality. Here is what protects your clients’ data, and where to check it.
Our DPA in brief
Summary of our data processing agreement
Swiss data protection law
Full compliance with the Federal Act on Data Protection (FADP) and its Ordinance (DPO). DPA and records of processing activities (ROPA) available on request.
Audit
SOC 2 Type II. Last audit by an independent auditor on 12 August 2026. Details of the controls in our trust center.
Data hosting
AWS, Zurich, Switzerland. Customer data and its backups are stored in Switzerland.
AI processing
On servers located in Europe (EU/EEA), through EU endpoints only.
Data retention
Our contracts with LLM providers impose zero data retention and forbid every model provider from using the data for training.
Encryption
In transit (TLS 1.2 or later) and at rest (AES-256 or equivalent).
Security testing
Annual penetration test by an independent firm, quarterly vulnerability scans, and critical vulnerabilities fixed within 7 days.
Access control
Multi-factor authentication is mandatory. Our personnel’s access is role-based, limited and logged.
Human approval
The agent writes to your systems only once a user approves, or where you have switched on autopilot for a workflow. Every agent action is logged.
Documents
Free 30-min AI audit