Applied AI, with security guardrails and human control
Advanced security aligned with OWASP for the construction industry. We protect your digital assets with proactive governance.
Company isolation
In Obrity, your company's information does not mix with that of other companies: projects, evidence, tasks, observations and reports are kept separate by design. This is key in multi-company (multi-tenant) software to prevent leaks and unauthorized access.
What it means for you (business value)
- Real confidentiality: your evidence (photos, videos, audios) and documents do not "appear" in another company.
- Less reputational and contractual risk: avoids the worst scenario: "the wrong report reached the client".
- Growth without losing control: you can manage multiple projects and users without sacrificing security.
How we do it (explained in executive language)
Data separation by company (logical isolation)
Each record within Obrity (project, evidence, task, etc.) is associated with your company and is only shown to authorized users within that company. Evidence (files) are stored and served from routes and permissions that respect the company. If a company requires an additional level, we offer a dedicated environment (enterprise option) to isolate even more.
"Context Vault" per company
Each organization can have its own "digital operational manual": templates, standards, checklists, nomenclatures, glossary and definition of "progress". This content only feeds the AI within your company: it is not reused or crossed with other companies.
AI with "closed" information retrieval per company (RAG)
Think of this as an intelligent search engine: before the AI responds, it first searches your documents and standards. The AI can only "see" and use content from your company, because access is filtered by company from the start of the process.
Mini-example that sells (very SME)
If your supervisor creates a weekly report, Obrity ensures that the report is assembled only with evidence and tasks from your company and your projects. No mixing, no 'accidents'.
OWASP Top 10 Standards for LLM
Prompt Injection
RiskInput manipulation to bypass system restrictions.
MitigationStrict prompt validation and semantic filtering layers before processing.
Sensitive Info Disclosure
RiskAccidental leakage of sensitive or confidential construction data.
MitigationEnd-to-end encryption and automatic anonymization of PII data.
Improper Output
RiskHallucinatory or inappropriate outputs that affect decision-making.
MitigationOutput guardrails and validation by human experts.
Excessive Agency
RiskAI taking unauthorized actions in external systems.
MitigationGranular "Least Privilege" permissions and continuous log monitoring.
AI Governance (NIST Framework)
GOVERN
Culture
Institutional risk management
MAP
Context
Threat identification
MEASURE
Analysis
Quantitative assessment
MANAGE
Action
Prioritization and response
Compliance and Privacy in Colombia and LATAM
We operate under the legal framework of Law 1581 of 2012, guaranteeing personal data protection. We clearly define the roles of Controller and Processor for total traceability.
Download DPA (Data Addendum)Controller
You maintain full ownership of the data entered.
Processor
Obrity processes information under your explicit instructions.
Questions for Management
How is the isolation of my data guaranteed?
Yes, with strict multi-tenant isolation at the database level. Your data is never used to train third-party global models without explicit consent.
Who has access to AI within my company?
Only roles you authorize via RBAC integrated with your identity provider. Administrators define which roles interact with which models and data sources.
How are AI interactions audited?
Yes. We maintain an immutable audit log of each query, the generated response and the context used, for periodic compliance reviews.