Security at Obert

Technical and organizational measures

Last updated: September 2026

This page describes the technical and organizational measures ("TOMs") that VENDI AI LTD, doing business as Obert, maintains to protect Personal Data processed through the Obert platform. It is the document referenced as the "Security Documentation" in our Data Processing Agreement, and it serves as Annex II of the Standard Contractual Clauses incorporated into that DPA.

These measures are implemented in accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. We may update this page as our infrastructure evolves. We will not materially reduce the overall level of security described here during the term of a customer agreement.

Where your data lives, in short

Obert's production infrastructure runs inside the European Union, in Frankfurt, Germany. Customer Data is stored in the EU by default, in an EU-managed PostgreSQL database.

Obert is operated by VENDI AI LTD, a company established in Israel. Israel is the subject of a European Commission adequacy decision under Article 45 of the GDPR, adopted in 2011 and confirmed in the Commission's review of existing adequacy decisions published in January 2024. Transfers of Personal Data from the EEA to Israel therefore require no additional transfer safeguards such as Standard Contractual Clauses.

A limited number of sub-processors process Personal Data in countries that are not covered by an adequacy decision. Each is named, with its purpose and location, in Schedule 2 of the DPA, and those transfers are covered by the Standard Contractual Clauses incorporated into the DPA.

1. Data residency and hosting

2. Data flow and retention at a glance

Stage Encryption Purpose Retention
Ingress
API, CSV import, LinkedIn and email connectors, website visitor tracking, webhooks
TLS 1.2 or higher Receive lead, account, and engagement data Held only for as long as needed to complete ingestion, then discarded or written to storage
Processing
Signals, ICP scoring, AI drafting and classification
TLS in transit, AES-256 at rest Qualify leads, score fit, draft and classify outreach Duration of the subscription. Model provider processes for inference only, with no training on Customer Data
Storage
PostgreSQL, Frankfurt
AES-256 at rest, plus application-level encryption for credential material Campaign execution, reporting, CRM sync Duration of the subscription, then 7 days to purge production and 35 days for backups to roll off
Egress
LinkedIn, email, outbound webhooks, CRM sync
TLS 1.2 or higher Deliver messages and synchronise records Copies persist in the customer's own channels and systems, outside Obert's control
Telemetry
Errors, traces, product analytics
TLS in transit, AES-256 at rest Reliability, debugging, abuse detection 90 days for error and trace telemetry, 12 months for product analytics

3. Encryption, pseudonymisation and data minimisation

3.1 Data in transit

3.2 Data at rest

3.3 Pseudonymisation and data minimisation

4. Access control

4.1 Customer access

4.2 Tenant isolation

4.3 Internal access

5. Personnel security

6. Endpoint and device security

7. Application security

8. Vulnerability and patch management

9. Logging and monitoring

10. Security incident response

11. Resilience, backup, and recovery

12. Secure development and change management

13. Testing and evaluating effectiveness

In accordance with Article 32(1)(d) of the GDPR, Obert maintains a process for regularly testing, assessing and evaluating the effectiveness of the measures described on this page.

14. Sub-processor management

15. Data retention and deletion

16. Certifications and audits

17. Contact

VENDI AI LTD, d.b.a Obert.io
Ibn Gabirol 72, Tel Aviv, Israel

Security: security@obert.io
Privacy and data protection: privacy@obert.io
Legal: legal@obert.io