DATA PRIVACY

A privacy promise you can draw as a boundary.

Obrenna keeps its cloud responsibilities intentionally narrow. The private data plane—where real work happens—runs in your organization's environment.

No prompt storage by default No plaintext MCP secrets Redacted operational telemetry
DATA RESPONSIBILITY

What goes where.

Configuration and operational metadata travel through the control plane. Sensitive work stays within the infrastructure your organization manages.

Obrenna cloudIdentity & control metadata
  • Account identity
  • Organization membership
  • Invitations
  • Device enrollment metadata
  • Machine and service health
  • Tool schema hashes
  • Policy configuration
  • Redacted confirmation metadata
Boundary enforced by architecture and policy
Organization infrastructurePrivate data plane
  • Prompts and chat history
  • Model inputs and outputs
  • MCP arguments and results
  • Private files and documents
  • Data-store responses
  • MCP credentials and API keys
  • Local model memory
  • Tool execution contents
NETWORK TRANSPARENCY

Know what is transmitted—and what is not.

Sent to the control plane

Authentication, membership operations, signed configuration sync, device heartbeats, health metadata and optional diagnostics.

Not sent by default

Prompts, chat content, documents, model outputs, MCP tool arguments, tool results, private API keys or data-store responses.

SECURITY IS SHARED WORK

Clear limits. No absolute claims.

Private AI can only be as secure as the systems it runs on. Obrenna provides controls; your organization remains responsible for its environment.

Local MCP executables are trusted software, not sandboxed code.
Schema approval confirms what changed; it does not prove a tool is safe.
VPN, endpoint security, backups and patching remain organizational duties.
Administrators control retention, telemetry and MCP configuration.