Why we built it
Passwords were built for a web of humans typing into forms. That world is ending. Agents now act on our behalf, credentials are phished and stuffed at industrial scale, and "log in" has quietly become the softest part of almost every system.
We kept seeing the same pattern: teams pour effort into their product, then bolt on an auth layer that stores password hashes, MFA seeds, and reset tokens — a pile of secrets that becomes the single most attractive thing to steal. The weakest link wasn't the product. It was the front door.
So we set out to make the front door the strongest part of the building — and to make its strength verifiable, not just asserted.
The mark is the message
Look at the Obelisk above — the Living Fortress. An alien castle rises from the abyss, its fractured obelisk a monument to permanence; a living flame crowns it, a signal that cannot be faked or extinguished. An energized O-seal orbits the structure like a force field. That outer ring is full-circle security: in the live mark its hue shifts with your security band and its lit segments reflect your real threat coverage in real time.
Two fidelities, one idea. The immersive Living Fortress above is the hero surface — the full idea rendered. Everywhere else — your nav, your app icon, your favicon — the flat Obelisk Seal carries the same DNA in a crisp, minimal form: a parametric ring, a clean obelisk, a crowned pyramidion. One brand, right-sized for every context. Your logo becomes your security posture.
Our mission
Make identity the strongest part of your stack, not the weakest — and make that strength provable. Passkey-first by default, no passwords or project secrets to steal, every consequential action sealed in a tamper-evident receipt, a never-lockout guarantee for the people who own the keys, and a single live security score anyone can act on. We call it full-circle security.
What makes Obelisk different
Plenty of providers will authenticate a user. Few will let you verify that they did it honestly. Obelisk's differences are structural, not cosmetic:
| Most identity providers | Obelisk |
|---|---|
| Password + optional MFA | Passkey-first — phishing-resistant by default |
| Your app stores credentials | Zero project secrets — nothing to leak |
| An audit log you're told exists | Hash-chained receipts you can verify |
| Lockout is your problem | Never-lockout guarantee, three layers — plus off-box disaster recovery, RTO ~15 min |
| One login for your app only | Be the IdP for your whole stack — OIDC and a SAML 2.0 IdP |
| "Trust our security" | A live Rating we run on ourselves, in public |
And one front door isn't just for your own app: Obelisk is a full OpenID Connect provider and a SAML 2.0 IdP — federate Cloudflare, 1Password, and Microsoft Entra over OIDC, and GitHub, Google Workspace, AWS, Slack, Atlassian and more over the SAML 2.0 IdP, every team tool inheriting the same passkey-first sign-in. Sites you don't even build on Obelisk can paste a live, un-forgeable “Secured by Obelisk Gate” seal on their login page.
The throughline: security you can prove, not just promise. See the full trust case →
How we build
Proof over promises. Honest by construction. No custom cryptography — only audited, node-native primitives, from Ed25519-signed receipts to a reserved post-quantum slot (the full cryptography reference). Assurance is bound at the credential level — a passkey session and a code-only session carry different grants by construction. And a simple rule we hold ourselves to: if we can't measure it, we don't claim it.
Who makes Obelisk
Obelisk is built and operated by VaultSpark Studios — and it's the security foundation our own products stand on. We run Obelisk on Obelisk: the same passkeys, the same receipts, the same never-lockout guarantee we offer you. We ship it to ourselves first.
Get in touch
Prefer a form? Send us a message →
Or email us directly — General hello@obeliskgate.com · Security security@obeliskgate.com · Privacy privacy@obeliskgate.com · Legal legal@obeliskgate.com
Ready to build on it? Integrate Obelisk · Why trust it · Create your account.