Product

What's new

A public-safe, plain-language log of what we've shipped. Newest first. Agents can read the same source as a versioned JSON document; internal work logs, infrastructure details, and security-sensitive operations stay private.

A sturdier mobile experience and safer release path

July 2026

Navigation now stays contained at every screen size, public controls meet a 44-pixel touch target, and contact links remain intact behind edge protections. An isolated staging environment proves the exact release before production, while runtime dependency updates are validated and swapped atomically with rollback to the prior service state. See the release posture →

Release history you — and your agents — can verify

July 2026

What's New now comes from one structured, public-safety-checked source. The same release history is available as JSON, carries stable entry identifiers, and is bound to the revision actually serving it. Open the release document →

Every deployment now proves the code it ships

July 2026

A production release must now have a successful continuous-integration result for the exact revision being deployed. The release boundary rejects missing, stale, malformed, still-running, or failed proof before it changes production. See the resilience posture →

Security evidence now carries its provenance

July 2026

Receipts and integrity evidence now distinguish interactive operators, trusted automation, and runtime environments without guessing. That closes a class of reports that looked authoritative while describing the wrong actor or source. How verification works →

Trust scores now respect evidence strength

July 2026

Security evidence is now weighted by authority and freshness, so a weak or old signal cannot silently carry the same confidence as a current, direct measurement. Explore the trust model →

Safety checks now prove they can catch a defect

July 2026

Critical checks are tested through the same arguments and wiring used in real operation. A check cannot be reported healthy merely because its underlying detector works in isolation. Read the security model →

Production status now follows the revision actually running

July 2026

Deployment-currency signals now compare the code serving production with the intended release, rather than treating unrelated repository files as runtime drift. View status and resilience →

Integrity reports identify the tree they measured

July 2026

Repository security evidence now states whether it measured committed code or a working copy. This prevents an uncommitted local change from being mistaken for production evidence. Review the security posture →

Unknown is no longer reported as healthy

July 2026

When a dependency or identity provider cannot be measured, Obelisk preserves that result as unknown instead of turning missing evidence into a green status. See how status is reported →

The website, brought fully current

July 2026

Sender-bound tokens are now documented for customers and developers, the API manifest covers federation and verification surfaces, every page carries the brand mark, and connector claims derive from one catalogue. Explore the API manifest →

Security alerts, API keys and full account control

July 2026

Your account now includes a security-alert timeline, scoped expiring API keys for agents, security-habit badges, and a direct account-deletion control. Open your account →

Live website roster

July 2026

Organization dashboards now show linked websites with live probe-backed status, response latency, and an uptime sparkline rather than a cached availability claim.

Theme and accessibility preferences that stick

July 2026

Light and dark themes now carry into browser chrome, while higher contrast, reduced motion, larger text, and other accessibility preferences are applied across the product.

Account Shield

July 2026

Every account now has a live security score, tier, trend, sign-in streak, and a concrete next action that can improve its posture.

The verified “Secured by Obelisk Gate” seal

June 2026

Protected sites can embed a live seal that reflects their measured security band and links to a public verification page — proof of protection rather than a static badge. Get the seal →

SAML 2.0 identity provider

June 2026

Obelisk can issue signed Security Assertion Markup Language assertions to downstream applications, making one passkey-first identity usable across compatible business tools. Set it up →

Off-box recovery and a self-healing watchdog

June 2026

Encrypted backups are integrity-checked away from the primary service, and the health watchdog can restart an unhealthy process. The documented total-loss recovery objective is about fifteen minutes. Resilience posture →

Integrations catalogue

June 2026

A single catalogue now shows where Obelisk can serve as the identity provider over OpenID Connect or Security Assertion Markup Language. Browse connectors →

Verify-it-yourself credential transparency

June 2026

Session issuance and passkey changes are recorded in a tamper-evident account log, so you can verify that each sign-in and credential change was yours.

Assurance-bound sessions

June 2026

Sessions carry how identity was proven. Passkey-backed sessions can perform sensitive changes; lower-assurance recovery sessions remain restricted.

The Obelisk Rating, 0–100

May 2026

A live security score distills measured account or organization signals into one rating with visible coverage and improvement levers.

Organizations, teams and website scan

May 2026

Register an organization, invite role-scoped team members, and measure a public website to produce a security rating with concrete improvement levers.

One identity, every project

May 2026

A universal Obelisk account now carries cleanly separated per-project profiles, allowing one passkey-first identity to work across the ecosystem.

Passkey-first usernameless sign-in

April 2026

One-tap, phishing-resistant sign-in works without typing a username, with controlled recovery paths available when needed.

Tamper-evident receipts

April 2026

Consequential identity and authorization actions emit signed, hash-chained receipts so the audit trail cannot be silently rewritten.