Enterprise-ready security you can trust

Trusted by the world’s largest network of Fortune 1000 and Global 2000 organizations to secure mission-critical SaaS.

Shield graphic representing Obsidian SaaS Security Posture Management (SSPM) solution

Trusted by Leading Companies

Enterprise readiness matters

Security leaders need proof, not promises.

Obsidian delivers enterprise-grade SaaS and AI security with verified controls, measurable compliance, and the operational resilience global organizations demand.

12-Month Historical Availability:

99.99%

more info

Resources

System Status

Stay informed with real-time platform health updates.

View status

Trust Center

Explore our certifications, controls, and policies.

Terms of Service
Data Processing Addendum (DPA)
Privacy Policy

Blog

Learn how Obsidian helps teams protect their SaaS and AI environments at scale.

Read blog

Obsidian delivers at scale

Enterprise-grade security controls

Granular Role-Based Access Control (RBAC) with full audit logging. Strict data segregation combining single-tenant resources with logically segmented multi-tenant infrastructure, including per-customer storage buckets and dedicated database schemas.

Uptime & reliability

Designed for enterprise-grade uptime, with automated failover within Availability Zones and redundancy across cloud infrastructure. Cross-region high availability is under development.

Global compliance & data sovereignty

Global footprint with regional data hosting in AWS US West 2 (Oregon), EU Central 1 (Frankfurt), and AP Southeast 2 (Sydney) — Saudi Arabia data center coming soon. Supports key compliance frameworks in-product, backed by SOC 2 Type 2, ISO 27001, ISO 27701, and IRAP attestations or certifications. ISO 42001 coming soon.

Proactive security posture

We conduct independent audits annually, including infrastructure and application penetration testing and periodic red team exercises across web apps, browser extensions, internal networks, cloud infrastructure, and corporate environments. All findings are prioritized and remediated promptly to ensure resilience.

Seamless operations integration

Flexible, out-of-the-box enterprise connections surface data on SaaS security for CMDB, TPRM, and GRC teams.

FAQs

How does Obsidian support compliance with regional data sovereignty laws?

Data is hosted regionally in dedicated AWS data centers according to customer location — US, EU/UK, or Australia. Our platform supports GDPR, HIPAA, CCPA, and other regional compliance mandates, as well as customer-specific contractual obligations and DPAs.

How does Obsidian protect customer data in multi-tenant environments?

Obsidian uses a hybrid architecture where some infrastructure is shared across tenants while sensitive customer data is strictly isolated in dedicated database schemas and storage buckets. Data is fully encrypted at rest and in motion with customer-dedicated encryption keys stored and managed in CSP-hosted secure key management systems. This approach balances operational efficiency with strong data segregation, security, and privacy controls. Obsidian also complies with applicable laws, customer agreements, and indexed Terms of Service, including Data Processing Agreements (DPAs), to ensure proper handling of customer data.

Where can I find Obsidian’s legal documents and policies?

Obsidian provides access to its key legal documents and policies, including the Terms of Service, Data Processing Addendum (DPA) and, Privacy Policy. These documents support compliance and transparency, giving customers clear guidance on legal and contractual obligations while using Obsidian’s platform.

What encryption standards does Obsidian use for data protection?

Customer data is encrypted at rest with AES 256-bit or higher and secured in transit using TLS 1.3.

Is there a secure development lifecycle (SDLC) process at Obsidian?

Yes. Our SDLC includes secure programming training, static code analysis, vulnerability scanning in CI/CD pipelines, and ongoing security validation. Automated and manual testing is performed along the code path from development through QE to production to ensure code quality and reliability.

How often does Obsidian conduct penetration testing?

We perform annual third-party penetration tests covering our web applications, browser extensions (Chrome and Firefox), internal networks, and cloud infrastructure. All identified issues are prioritized and remediated swiftly.

Does Obsidian have a responsible disclosure program?

Yes, we welcome responsible vulnerability disclosures and manage reports according to our Responsible Disclosure Policy, available publicly. However, we currently do not offer monetary rewards for disclosures.

How does Obsidian handle product or security incidents?

Obsidian ensures timely detection, notification, and resolution of product and security incidents. All incidents are posted to our public status page, and impacted customers receive direct notifications via email, Slack, or TAM engagement, including relevant indicators of compromise and recommended actions. Historical incident data is available here. Initial communications focus on timely disclosure, with detailed analysis provided subsequently. Follow-up support is provided in accordance with contractual obligations and internal procedures.

How does Obsidian handle data backup and disaster recovery?

We perform daily backups with monthly full backups and retain raw data for 30 days by default. Our tested Business Continuity & Disaster Recovery Plan ensures data integrity and availability. While we leverage multiple Availability Zones (AZs) in AWS and GCP for redundancy, cross-region high availability is currently under development for select environments. Automated failover is supported within AZs at both component and cluster levels.

What uptime SLAs does Obsidian provide?

We deliver enterprise-grade SLAs, with Obsidian’s standard services achieving 99.99% uptime from August 2024 through August 2025—a level of reliability that exceeds typical industry standards. Availability is tracked continuously. Services are designed for high availability, with automated failover within Availability Zones. Incidents are managed promptly to resolve issues quickly, minimize third-party risk, and align with your organization’s risk tolerance.

What deployment models does Obsidian support?

Obsidian is a SaaS-native platform designed for cloud-first deployment, optimized for global scalability and security.

Can customers export their data easily?

Yes. We provide comprehensive data export via APIs, including audit logs and configuration changes, in accordance with applicable laws, DPAs, and indexed Terms of Service.