Obligia Back to site
Security & trust

Built for the financial sector, from the ground up.

Your contract data is confidential. Obligia is engineered so it stays that way, with the controls a regulated entity expects.

Encryption everywhere

Encrypted in transit (TLS), and encrypted at rest by our hosting provider. Passwords are hashed with argon2id (memory-hard), never stored in clear.

Per-tenant isolation

Every record is scoped to your organisation on every request, and the boundary is covered by automated tests that fail the build if it is ever crossed.

Two-factor authentication

TOTP 2FA with the secret encrypted at rest. A stolen password alone can't open an account.

Audit trail

Sensitive actions (logins, credential changes, exports, member changes) are recorded in an audit log, retained for 36 months.

EU hosting & GDPR

Data hosted in the European Union. No third-party front-end requests; account deletion (right to erasure) built in, and your register is exportable in the regulator's own format at any time.

Hardened by design

Strict Content-Security-Policy, anti-clickjacking headers, request-body caps, rate limiting, signature-verified billing webhooks, and fail-closed configuration.

Data handling

We only ever hold what the register needs.

The operator back-office shows aggregates and metadata only, never the contents of your register. Your business data is processed solely on your behalf.

  • No third-party trackers; fonts are self-hosted.
  • Privacy-preserving analytics: no cookies, no stored IPs.
  • Least data: we don't ask for anything the register doesn't require.
  • Right to erasure: delete your account and data at any time.

An independent penetration test is planned before onboarding production client data. For our full posture and disclosure policy, see Privacy (GDPR) and contact us at obligia.ceo@gmail.com.

Ready to build your DORA register on secure ground?

Compliant, validated, and confidential from day one.

Get started now