---
title: "Security & Privacy"
description: "Practical guidance on AI agent security, privacy, data handling, and deployment hardening."
canonical: "https://deploy-hermes.com/security-privacy"
---

# Security & Privacy

> Practical guidance on AI agent security, privacy, data handling, and deployment hardening.

Canonical: https://deploy-hermes.com/security-privacy

AI agents touch tokens, prompts, channels, and memory. These pages clarify where the real security risks are and which controls actually reduce them.

Security and privacy are product decisions, not afterthoughts.

## Pages in this category

- [AI Agent Security](/security-privacy/ai-agent-security): A practical guide to AI agent security risks, controls, and deployment choices that actually reduce exposure.
- [Security Hardening Checklist](/security-privacy/security-hardening-checklist): A security hardening checklist for AI agent deployments covering credentials, access, logging, channels, and recovery.
- [Privacy-First AI Agents](/security-privacy/privacy-first-ai-agents): What privacy-first AI agents require in practice, from credential boundaries to retention choices and provider strategy.
- [AI Privacy Myths](/security-privacy/ai-privacy-myths): Common myths about AI privacy, including assumptions about local models, hosted APIs, logs, and what 'private' really means.
- [Data Residency for AI Agents](/security-privacy/data-residency-for-ai-agents): How to think about data residency for AI agents, including deployment regions, provider paths, and operational implications.
- [Grok Bot Security: Keys, Channels, and Agent Controls](/security-privacy/grok-bot-security): Secure a Grok bot by protecting the xAI key, narrowing Telegram access, limiting tools, and verifying the complete agent boundary.

---

- [Full documentation index](/llms.txt)
- [Complete site text](/llms-full.txt)
- [Developer portal](/developers)
- [OpenAPI contract](/openapi.json)
- [MCP server card](/.well-known/mcp.json)
