Trust

How Obligary is built to be trusted

A clear summary of how Obligary protects workspace access, handles private evidence and keeps product responsibilities clear.

Need to review Obligary for a customer or supplier assessment?

Request proportionate due-diligence information or report a security concern through the monitored support address.

Email hello@obligary.co.uk

Role-based workspace access

Owners, admins, members and viewers receive different permissions inside organisation workspaces.

Separate client workspaces

Each client organisation has its own membership, task, evidence and reporting boundary inside an authorised agency portfolio.

Private evidence handling

Evidence files are stored privately and downloads use signed access links.

Operational email trails

Invites, reminders and task assignment notifications keep work visible to the right people.

Billing separation

Obligary is operated by Web Wonderland Ltd, with Stripe used for checkout, invoices and payment receipts.

Product boundary

Obligary is a calendar, reminder, evidence and reporting tool operated by Web Wonderland Ltd. It supports good compliance administration, but it does not replace specialist judgement, certify organisations or make submissions to public bodies.

Identity and access

Protected app areas use Clerk-authenticated users mapped to local Obligary user records. Organisation routes check membership and role before exposing workspace data or allowing changes.

The current permission model distinguishes owners, admins, members and viewers. Billing and settings are restricted more tightly than read-only workspace views.

Client workspace separation

A client managed through an agency portfolio remains a separate organisation workspace. Membership and role checks are evaluated against that organisation before workspace records are read or changed. Agency users can switch into client workspaces they are authorised to manage; this does not combine client task, evidence or report records into one shared tenant.

Client users are invited only to their own organisation. Secure evidence-request links are scoped to a specific request and do not grant general workspace access.

Infrastructure and service providers

Core infrastructure

Application hosting is on Vercel, application data is stored in PostgreSQL with Neon, and evidence files use Cloudflare R2-compatible private object storage.

Specialist services

Authentication is handled by Clerk, transactional email is sent through Resend, and subscription billing, invoices and receipts are handled by Stripe.

The current service-provider list is available on the subprocessors page.

Evidence and records

Private file pathing

Evidence storage keys include organisation context and generated identifiers rather than trusting public filenames.

Signed downloads

Evidence download actions issue time-limited signed URLs after organisation access has been checked.

Audit logs record important workspace actions such as organisation setup, team changes and task-related changes where those flows are implemented.

Backups, recovery and assurance boundaries

Obligary uses managed hosting, database and private object-storage providers. Provider capabilities are only one part of recovery readiness, so this public page does not claim a particular recovery time, recovery point, independent certification or universal backup coverage that has not been separately verified.

Customers carrying out supplier due diligence can request the current, proportionate recovery and operational evidence available for review by emailing hello@obligary.co.uk.

Security concerns and incident reporting

Suspected unauthorised access, exposed links, unexpected account activity or other security concerns should be reported promptly to hello@obligary.co.uk. Include enough information to identify the affected workspace and event, but do not send passwords, authentication codes or unnecessary sensitive records by email.

Web Wonderland Ltd will assess the report, preserve appropriate operational evidence and contact affected parties where required by the applicable response and data-protection obligations. This contact route does not replace an organisation's own incident-response duties.

What customers should not store

Obligary is not designed to store HMRC credentials, Companies House authentication codes, bank login details, card details, passwords, unnecessary sensitive personal data, personal identity documents or one-time verification codes. Where evidence contains sensitive information, workspace owners should check that storage is necessary and that access is limited to the right people.

Customer responsibilities

Workspace owners are responsible for inviting the right users, choosing roles carefully, reviewing evidence, removing access when people leave, setting appropriate retention practices and deciding when professional advice is needed.

Operational surfaces

  • Reminder jobs send upcoming, due and overdue task emails while avoiding duplicate reminder rows.
  • Task assignment emails point users back to work assigned to them.
  • Stripe billing flows manage checkout, subscription state, invoices and customer billing portal access.
  • Reports and exports reflect the current organisation or agency roll-up view selected by the user.

Data processing

For many customer workspace records, Web Wonderland Ltd operates Obligary as a processor acting on the customer organisation's instructions. A practical summary is available in the data processing terms.

Questions

Contact hello@obligary.co.uk about these pages or open the Obligary help desk.