Policy center

Security & Compliance

Clear operating policies for teams evaluating OggyCloud across cloud, SaaS, and LLM cost workflows.

Last updated: April 25, 2026

1. Read-Only Access Model

OggyCloud is designed around least-privilege provider access. Use read-only roles or scoped tokens wherever the provider supports them.

Optimization recommendations are surfaced for human review. OggyCloud does not make infrastructure changes automatically by default.

2. Credential And Data Handling

Provider credentials are stored encrypted and limited to the minimum permissions needed for billing, inventory, and usage visibility.

Prompt and response capture for AI usage remains opt-in, with retention controls and payload redaction for enterprise deployments.

3. Compliance Status

OggyCloud is pre-SOC 2 unless a signed security packet or trust report states otherwise.

Enterprise security options include SSO, expanded RBAC, audit logs, data retention controls, and compliance review through sales.

Questions about our policies?

Our legal and security teams are available to discuss our compliance framework with your security officers.

Contact Legal Team

Need a security or policy review?

Share your vendor review questions with us and we will help your team evaluate OggyCloud for cloud, SaaS, and AI spend operations.