Skip to main content

Applied AI, with security guardrails and human control

Advanced security aligned with OWASP for the construction industry. We protect your digital assets with proactive governance.

Full compliance with Law 1581

Company isolation

In Obrity, your company's information does not mix with that of other companies: projects, evidence, tasks, observations and reports are kept separate by design. This is key in multi-company (multi-tenant) software to prevent leaks and unauthorized access.

What it means for you (business value)

  • Real confidentiality: your evidence (photos, videos, audios) and documents do not "appear" in another company.
  • Less reputational and contractual risk: avoids the worst scenario: "the wrong report reached the client".
  • Growth without losing control: you can manage multiple projects and users without sacrificing security.

How we do it (explained in executive language)

Data separation by company (logical isolation)

Each record within Obrity (project, evidence, task, etc.) is associated with your company and is only shown to authorized users within that company. Evidence (files) are stored and served from routes and permissions that respect the company. If a company requires an additional level, we offer a dedicated environment (enterprise option) to isolate even more.

"Context Vault" per company

Each organization can have its own "digital operational manual": templates, standards, checklists, nomenclatures, glossary and definition of "progress". This content only feeds the AI within your company: it is not reused or crossed with other companies.

AI with "closed" information retrieval per company (RAG)

Think of this as an intelligent search engine: before the AI responds, it first searches your documents and standards. The AI can only "see" and use content from your company, because access is filtered by company from the start of the process.

Mini-example that sells (very SME)

If your supervisor creates a weekly report, Obrity ensures that the report is assembled only with evidence and tasks from your company and your projects. No mixing, no 'accidents'.

OWASP Top 10 Standards for LLM

Prompt Injection

RiskInput manipulation to bypass system restrictions.

MitigationStrict prompt validation and semantic filtering layers before processing.

Sensitive Info Disclosure

RiskAccidental leakage of sensitive or confidential construction data.

MitigationEnd-to-end encryption and automatic anonymization of PII data.

Improper Output

RiskHallucinatory or inappropriate outputs that affect decision-making.

MitigationOutput guardrails and validation by human experts.

Excessive Agency

RiskAI taking unauthorized actions in external systems.

MitigationGranular "Least Privilege" permissions and continuous log monitoring.

AI Governance (NIST Framework)

GOVERN

Culture

Institutional risk management

MAP

Context

Threat identification

MEASURE

Analysis

Quantitative assessment

MANAGE

Action

Prioritization and response

Compliance and Privacy in Colombia and LATAM

We operate under the legal framework of Law 1581 of 2012, guaranteeing personal data protection. We clearly define the roles of Controller and Processor for total traceability.

Download DPA (Data Addendum)

Controller

You maintain full ownership of the data entered.

Processor

Obrity processes information under your explicit instructions.

Questions for Management

How is the isolation of my data guaranteed?

Yes, with strict multi-tenant isolation at the database level. Your data is never used to train third-party global models without explicit consent.

Who has access to AI within my company?

Only roles you authorize via RBAC integrated with your identity provider. Administrators define which roles interact with which models and data sources.

How are AI interactions audited?

Yes. We maintain an immutable audit log of each query, the generated response and the context used, for periodic compliance reviews.

Security and Privacy

Data protection and regulatory compliance

Talk to our team