Trust and security
What we hold, where your data lives, and what we do not have yet
Everything on this page is written plainly and kept current. Where we do not yet hold something, it is marked as not held rather than left out.
Where we stand
What we hold today, and what we do not. We would rather publish a date than a badge.
WCAG 2.1 AA
Every interface is designed and tested to WCAG 2.1 AA. No independent audit yet.
In place
GDPR and Australian Privacy Act
Data processing agreement, subject access and erasure are built and working.
In place
SOC 2
Not yet held. We will publish the date we start the audit.
Not yet held
ISO 27001
Not yet held. We will publish the date we start certification.
Not yet held
Where your data lives
Each region is an independent stack, and your data stays in the region you choose. Only the keys our own operations need are shared between regions. Australia is the region we run today, and the others are marked as planned rather than listed as though you could pick one now.
Australia (Sydney)
Our launch region. Data for Australian customers is stored and processed here.ap-southeast-2
Live
Europe (Ireland)
European Union and GDPR residency, on the same architecture, brought up as we take on European customers.eu-west-1
Planned
United States (N. Virginia)
United States residency, on the same architecture, brought up as we take on customers there.us-east-1
Planned
How your data is protected
Four things we do with every workspace, whichever modules you use.
Separated for every customer
Your records are kept apart from the records of every other customer. The separation is applied by the application and again by the database, and an automated test that tries to read data belonging to another organisation runs on every build. If it ever succeeded, the release would stop.
Encrypted in transit and in storage
Everything sent between your people and Obliwise travels over an encrypted connection, and the records and files we hold are encrypted where they are stored. Health records sit behind their own separate keys.
Evidence cannot be altered once written
Compliance evidence is written once and cannot be changed or removed afterwards, and every file is recorded in an inventory as it is stored, so a later alteration would show. Signing that inventory with our own production key is not switched on yet, and we say so here rather than implying otherwise.
Health information is restricted and logged
Injury and health records are open only to people who have been given clinical access, and every time one is read it is recorded. Emergency access needs a written reason, raises an alert at the time, and the log of those reads is checked daily.
AI is optional and off by default
You switch it on purpose by purpose, and you can switch it off again at any time.
Off until you turn it on
Every AI feature is optional and off by default, purpose by purpose. No data reaches an AI provider unless you enable it, and one control turns AI off again across your whole workspace.
A person decides, every time
AI output is never written into your records on its own. Every suggestion is a draft that a person has to read and accept, and the person who asked for it cannot be the person who approves it.
Personal details removed first
If you do enable AI, personal details are stripped out of the text before it reaches any model. Providers receive the redacted version only, never raw personal or health information.
Providers that may handle your data
The complete list, taken from the same reviewed record our customers receive, so this page and the platform say the same thing.
| Provider | What it does | Australian customers | Other regions | When it is used |
|---|---|---|---|---|
| Amazon Web Services | Cloud infrastructure hosting (computing, file storage, messaging and encryption) for all customer data and evidence. | Sydney (ap-southeast-2) | Ireland (European customers), N. Virginia (United States customers) | Always |
| Amazon SES | Email delivery for notifications, acknowledgement prompts and report links. | Sydney (ap-southeast-2) | Ireland (European customers), N. Virginia (United States customers) | Always |
| Twilio SendGrid | Backup email provider, used only if the email service in your own region is unavailable. | United States / European Union | Same for all regions | Always |
| Anthropic | AI model provider for optional AI features such as drafting help and form assistance. Receives redacted text only, because personal details are removed before anything leaves the platform. | United States (API) | Same for all regions | Only if you turn the feature on Only if you turn AI on. Off by default. |
| OpenAI | Alternative AI model provider, used only where a customer chooses the OpenAI route. Receives redacted text only. | United States (API) | Same for all regions | Only if you turn the feature on Only if you turn AI on and choose OpenAI. |
| Twilio | Text message delivery for notifications and alert acknowledgements. | United States / European Union | Same for all regions | Only if you turn the feature on Only if you turn on text message notifications. |
| Open-Meteo | Historical weather observations for incident context. Receives map coordinates and a date only, never any customer, personal or health information. | European Union (Germany) | Same for all regions | Only if you turn the feature on Only if you enable weather context. |
For Australian customers, safety records and evidence are stored and processed in Sydney and never leave the region. Optional providers handle your data only if you enable the feature, and AI providers receive redacted text only. The backup email provider may carry notification content if the service in your own region is unavailable. A data processing agreement is available on request.
Billing for your Obliwise subscription is handled by Stripe. It processes account and payment details for our commercial relationship only and never receives any data from inside your Obliwise workspace, so it is not a sub-processor of your safety data.
Bring your security questionnaire.
Book a session and we will walk through where your data is held, who can reach it and what the record of access looks like, with the answers in front of you.