Need to review Obligary for a customer or supplier assessment?
Request proportionate due-diligence information or report a security concern through the monitored support address.
Role-based workspace access
Owners, admins, members and viewers receive different permissions inside organisation workspaces.
Separate client workspaces
Each client organisation has its own membership, task, evidence and reporting boundary inside an authorised agency portfolio.
Private evidence handling
Evidence files are stored privately and downloads use signed access links.
Operational email trails
Invites, reminders and task assignment notifications keep work visible to the right people.
Billing separation
Obligary is operated by Web Wonderland Ltd, with Stripe used for checkout, invoices and payment receipts.
Product boundary
Obligary is a calendar, reminder, evidence and reporting tool operated by Web Wonderland Ltd. It supports good compliance administration, but it does not replace specialist judgement, certify organisations or make submissions to public bodies.
Identity and access
Protected app areas use Clerk-authenticated users mapped to local Obligary user records. Organisation routes check membership and role before exposing workspace data or allowing changes.
The current permission model distinguishes owners, admins, members and viewers. Billing and settings are restricted more tightly than read-only workspace views.
Client workspace separation
A client managed through an agency portfolio remains a separate organisation workspace. Membership and role checks are evaluated against that organisation before workspace records are read or changed. Agency users can switch into client workspaces they are authorised to manage; this does not combine client task, evidence or report records into one shared tenant.
Client users are invited only to their own organisation. Secure evidence-request links are scoped to a specific request and do not grant general workspace access.
Infrastructure and service providers
Core infrastructure
Application hosting is on Vercel, application data is stored in PostgreSQL with Neon, and evidence files use Cloudflare R2-compatible private object storage.
Specialist services
Authentication is handled by Clerk, transactional email is sent through Resend, and subscription billing, invoices and receipts are handled by Stripe.
The current service-provider list is available on the subprocessors page.
Evidence and records
Private file pathing
Evidence storage keys include organisation context and generated identifiers rather than trusting public filenames.
Signed downloads
Evidence download actions issue time-limited signed URLs after organisation access has been checked.
Audit logs record important workspace actions such as organisation setup, team changes and task-related changes where those flows are implemented.
Backups, recovery and assurance boundaries
Obligary uses managed hosting, database and private object-storage providers. Provider capabilities are only one part of recovery readiness, so this public page does not claim a particular recovery time, recovery point, independent certification or universal backup coverage that has not been separately verified.
Customers carrying out supplier due diligence can request the current, proportionate recovery and operational evidence available for review by emailing hello@obligary.co.uk.
Security concerns and incident reporting
Suspected unauthorised access, exposed links, unexpected account activity or other security concerns should be reported promptly to hello@obligary.co.uk. Include enough information to identify the affected workspace and event, but do not send passwords, authentication codes or unnecessary sensitive records by email.
Web Wonderland Ltd will assess the report, preserve appropriate operational evidence and contact affected parties where required by the applicable response and data-protection obligations. This contact route does not replace an organisation's own incident-response duties.
What customers should not store
Obligary is not designed to store HMRC credentials, Companies House authentication codes, bank login details, card details, passwords, unnecessary sensitive personal data, personal identity documents or one-time verification codes. Where evidence contains sensitive information, workspace owners should check that storage is necessary and that access is limited to the right people.
Customer responsibilities
Workspace owners are responsible for inviting the right users, choosing roles carefully, reviewing evidence, removing access when people leave, setting appropriate retention practices and deciding when professional advice is needed.
Operational surfaces
- Reminder jobs send upcoming, due and overdue task emails while avoiding duplicate reminder rows.
- Task assignment emails point users back to work assigned to them.
- Stripe billing flows manage checkout, subscription state, invoices and customer billing portal access.
- Reports and exports reflect the current organisation or agency roll-up view selected by the user.
Data processing
For many customer workspace records, Web Wonderland Ltd operates Obligary as a processor acting on the customer organisation's instructions. A practical summary is available in the data processing terms.
