Security built on transparency
Cobl keeps your data safe and compliant, with maximum control

Privacy by Design
Agent guardrails
Run Cobl your way
Choose the deployment model that fits your security and compliance requirements
European cloud
By default, Cobl data is hosted in Dublin.
Data hosted in Europe
Cobl runs on Vercel's dub1 region in Dublin, Ireland. All application data stays within the European Union. Product analytics go through PostHog EU (eu.i.posthog.com). No data transits through US infrastructure for core application operations.

SOC 2 Type 2 and ISO 27001 certified
Vercel holds SOC 2 Type 2, ISO 27001:2013, and PCI DSS v4.0 certifications. These cover the infrastructure Cobl runs on: compute, networking, storage, and deployment pipeline. Vercel also maintains GDPR compliance with a Data Processing Addendum and participates in the Data Privacy Framework. Cobl itself holds no independent certification today.
AES-256 encryption with WAF and DDoS protection
Vercel encrypts data at rest with AES-256 and in transit with TLS. All Cobl traffic benefits from automatic DDoS mitigation and managed WAF rulesets covering the OWASP Top 10. Cobl does not manage encryption keys at the application level: no field-level encryption, no dedicated KMS.
Regular third-party penetration testing
Vercel runs third-party penetration tests on a regular cycle, alongside daily code reviews, static analysis, and dependency scanning. Full details at vercel.com/security. Cobl also run its own independent penetration tests with Exodata.
Private Cloud (AWS or Azure)
Deploy in your own account for complete control.
On-Premise
Run cobl fully inside your infrastructure.
FAQs
Quick answers to help you get started with cobl
Contact us at contact@cobl.ai to receive documentation on costs, timelines, and support.





.jpg)

.jpg)




