A sturdier mobile experience and safer release path
July 2026
Navigation now stays contained at every screen size, public controls meet a 44-pixel touch target, and contact links remain intact behind edge protections. An isolated staging environment proves the exact release before production, while runtime dependency updates are validated and swapped atomically with rollback to the prior service state. See the release posture →
Release history you — and your agents — can verify
July 2026
What's New now comes from one structured, public-safety-checked source. The same release history is available as JSON, carries stable entry identifiers, and is bound to the revision actually serving it. Open the release document →
Every deployment now proves the code it ships
July 2026
A production release must now have a successful continuous-integration result for the exact revision being deployed. The release boundary rejects missing, stale, malformed, still-running, or failed proof before it changes production. See the resilience posture →
Security evidence now carries its provenance
July 2026
Receipts and integrity evidence now distinguish interactive operators, trusted automation, and runtime environments without guessing. That closes a class of reports that looked authoritative while describing the wrong actor or source. How verification works →
Trust scores now respect evidence strength
July 2026
Security evidence is now weighted by authority and freshness, so a weak or old signal cannot silently carry the same confidence as a current, direct measurement. Explore the trust model →
Safety checks now prove they can catch a defect
July 2026
Critical checks are tested through the same arguments and wiring used in real operation. A check cannot be reported healthy merely because its underlying detector works in isolation. Read the security model →
Production status now follows the revision actually running
July 2026
Deployment-currency signals now compare the code serving production with the intended release, rather than treating unrelated repository files as runtime drift. View status and resilience →
Integrity reports identify the tree they measured
July 2026
Repository security evidence now states whether it measured committed code or a working copy. This prevents an uncommitted local change from being mistaken for production evidence. Review the security posture →
Unknown is no longer reported as healthy
July 2026
When a dependency or identity provider cannot be measured, Obelisk preserves that result as unknown instead of turning missing evidence into a green status. See how status is reported →
The website, brought fully current
July 2026
Sender-bound tokens are now documented for customers and developers, the API manifest covers federation and verification surfaces, every page carries the brand mark, and connector claims derive from one catalogue. Explore the API manifest →
Security alerts, API keys and full account control
July 2026
Your account now includes a security-alert timeline, scoped expiring API keys for agents, security-habit badges, and a direct account-deletion control. Open your account →
Live website roster
July 2026
Organization dashboards now show linked websites with live probe-backed status, response latency, and an uptime sparkline rather than a cached availability claim.
Theme and accessibility preferences that stick
July 2026
Light and dark themes now carry into browser chrome, while higher contrast, reduced motion, larger text, and other accessibility preferences are applied across the product.
Account Shield
July 2026
Every account now has a live security score, tier, trend, sign-in streak, and a concrete next action that can improve its posture.
The verified “Secured by Obelisk Gate” seal
June 2026
Protected sites can embed a live seal that reflects their measured security band and links to a public verification page — proof of protection rather than a static badge. Get the seal →
SAML 2.0 identity provider
June 2026
Obelisk can issue signed Security Assertion Markup Language assertions to downstream applications, making one passkey-first identity usable across compatible business tools. Set it up →
Off-box recovery and a self-healing watchdog
June 2026
Encrypted backups are integrity-checked away from the primary service, and the health watchdog can restart an unhealthy process. The documented total-loss recovery objective is about fifteen minutes. Resilience posture →
Integrations catalogue
June 2026
A single catalogue now shows where Obelisk can serve as the identity provider over OpenID Connect or Security Assertion Markup Language. Browse connectors →
Verify-it-yourself credential transparency
June 2026
Session issuance and passkey changes are recorded in a tamper-evident account log, so you can verify that each sign-in and credential change was yours.
Assurance-bound sessions
June 2026
Sessions carry how identity was proven. Passkey-backed sessions can perform sensitive changes; lower-assurance recovery sessions remain restricted.
The Obelisk Rating, 0–100
May 2026
A live security score distills measured account or organization signals into one rating with visible coverage and improvement levers.
Organizations, teams and website scan
May 2026
Register an organization, invite role-scoped team members, and measure a public website to produce a security rating with concrete improvement levers.
One identity, every project
May 2026
A universal Obelisk account now carries cleanly separated per-project profiles, allowing one passkey-first identity to work across the ecosystem.
Passkey-first usernameless sign-in
April 2026
One-tap, phishing-resistant sign-in works without typing a username, with controlled recovery paths available when needed.
Tamper-evident receipts
April 2026
Consequential identity and authorization actions emit signed, hash-chained receipts so the audit trail cannot be silently rewritten.