Oblix
Security & GDPR

Your clients' data stays on your server, behind one locked door

Oblix runs as a self-hosted Docker stack on your own VPS, with every public request entering through a single Cloudflare Tunnel — so there are no public ports to attack. Secrets are encrypted, sensitive actions are audited, and GDPR controls sit in Settings.

Oblix is an accountancy operating system that runs as a self-hosted Docker stack on your own VPS, with all public traffic entering through a single Cloudflare Tunnel so the server exposes no public ports. Third-party credentials and sensitive secrets are encrypted at rest with AES-256-GCM, sensitive actions are recorded to an audit trail, and GDPR tooling covers consent capture, automatic screenshot retention, data-subject export and erasure.

  • Runs entirely on your own VPS as a Docker Compose stack — app, worker, database, object storage and e-signatures in your own containers
  • Routes all public traffic through a single Cloudflare Tunnel, so the server exposes no public ports
  • Encrypts third-party credentials and sensitive secrets with AES-256-GCM before they reach the database
  • Records sensitive actions to an audit trail — who did what, to what, when, and from which IP
  • Captures and versions consent for staff monitoring, file uploads and client onboarding
  • Auto-purges Companion screenshots on a short retention window, and provides data-subject export and erasure tooling

The question every principal has to answer

You hold years of client records, UTRs, payroll data and bank details. Before you put any of that into a new system, you have to be able to tell a worried client — or the ICO — exactly where the data lives, who can reach it, and what happens when someone asks to be forgotten. Most practice tools are someone else's cloud: your client list sits in a database you don't control, behind ports you can't see, governed by a privacy policy you didn't write. That is a hard thing to stand behind.

What you get instead

Oblix runs on a server you own. There is no public front door to the application — all traffic comes in through a single Cloudflare Tunnel, and the server itself exposes no public ports. The credentials that connect Oblix to QuickBooks, Microsoft 365, Companies House and HMRC are encrypted before they are stored. Sensitive actions are written to an audit trail you can read, and the GDPR controls a practice actually needs — consent records, retention, data-subject export and erasure — sit in one settings area rather than in a support ticket to a vendor.

How the protection works

Four layers, each doing one job, with nothing depending on you remembering to configure it.

Self-hosted on your own VPS

Oblix ships as a Docker Compose stack — the app, background worker, PostgreSQL database, Redis, MinIO object storage, nginx and DocuSeal e-signatures all run in your own containers, on infrastructure you control. Your data never has to live in a shared multi-tenant cloud.

No public ports, one tunnel in

In production every public request enters through a single Cloudflare Tunnel. nginx and every service stay on a private internal Docker network, and the VPS exposes no public ports for an attacker to find or scan.

Secrets encrypted at rest

OAuth tokens for QuickBooks and Microsoft 365, HMRC credentials, MFA secrets and other sensitive fields are encrypted with AES-256-GCM (authenticated encryption) inside the application before they are written to the database.

Sensitive actions audited

Client and job changes, role changes, integration connects and disconnects, data exports, erasures and outbound prospecting sends are recorded to an audit trail capturing the user, the action, the target, the timestamp and the IP address.

GDPR controls where you can see them

Consent is captured and versioned — staff monitoring and file-upload consent in the desktop Companion, and client GDPR and ethics consent during onboarding — with each event audited and re-affirmed if the wording changes. The Companion's screenshots are auto-purged on a short retention window every night. For data-subject requests, a person can export their own data as a ZIP (Article 15), and a manager can run an erasure that anonymises a person while preserving the records you are legally required to keep, such as audit, billing and AML (Article 17). The GDPR settings page shows live retention figures for clients, communications, screenshots and audit, so you can see your position rather than guess at it.

What we don't claim

We would rather be precise than impressive. Only Companion screenshot retention is fully automatic — erasing a client's communications and documents is a deliberate, manager-driven action, not a one-click background sweep, and the GDPR page says so plainly. Encryption protects specific secret fields and credentials, not every byte of business data. The audit trail is an application-level log in your database, not a tamper-proof WORM store. And while the server exposes no public ports, it still calls external APIs — Companies House, QuickBooks, Microsoft Graph and so on — whenever you use those features, so it isn't air-gapped.

What it gives the practice.

Self-hostable Docker Compose stack on your own VPS

Your client list and records live on infrastructure you own and control — not in a vendor's shared cloud.

All public traffic enters through one Cloudflare Tunnel; no public ports on the VPS

There is no public front door for an attacker to scan or hit directly.

AES-256-GCM encryption of credentials and secrets before they reach the database

Stored QuickBooks, Microsoft 365 and HMRC credentials are protected even if a database file is read.

Audit trail of sensitive actions with user, target, time and IP

You can answer 'who changed this, and when' for clients, jobs, integrations and data requests.

Versioned consent capture for monitoring, file uploads and client onboarding

You hold a dated record of consent you can show a client or regulator.

Automatic screenshot retention plus data-subject export and erasure tooling

You can meet a right-of-access or right-to-be-forgotten request without a vendor in the loop.

Questions practices ask

Where is our client data actually stored?

On your own server. Oblix is a self-hosted Docker Compose stack — the application, background worker, PostgreSQL database, Redis, MinIO object storage, nginx and DocuSeal e-signatures all run in containers on a VPS you control. Your data does not have to live in a shared multi-tenant cloud.

How does Oblix avoid exposing the server to the internet?

In production all public traffic enters through a single Cloudflare Tunnel, which is the only ingress, so the VPS exposes no public ports. nginx and every other service stay on a private internal Docker network and are never reachable directly from the internet. There is no public application port for an attacker to scan or connect to.

Is our data encrypted?

Sensitive credentials and secrets are encrypted at rest with AES-256-GCM authenticated encryption before they are written to the database — including QuickBooks and Microsoft 365 OAuth tokens, HMRC credentials and MFA secrets. This is application-layer field encryption of specific secret fields, not encryption of every byte of general business data, and its security depends on keeping the encryption key secret. We don't claim full-disk or end-to-end encryption of all data.

Can we handle a GDPR data-subject request?

Yes. A person can export their own data as a ZIP under Article 15, and a manager can run an Article 17 erasure that anonymises an individual while preserving records you must legally keep, such as audit, billing and AML. Companion screenshots are auto-purged nightly on a short retention window; note that erasing a client's communications and documents is a deliberate manager action rather than a fully automatic background sweep, and the GDPR settings page states this clearly.

Do you keep a record of who did what?

Yes. Sensitive actions across Oblix — client and job changes, role changes, integration connects and disconnects, data exports and erasures, and prospecting sends — are written to an audit trail recording the user, the action, the target, the timestamp and the IP address. It is an application-level audit log in your own database, broad in coverage but not a cryptographically tamper-proof WORM store.

Oblix

Give the practice one place to see the work.

Bring every client, job, deadline, document, chargeable hour and client conversation into a single operating view for the whole firm.

© 2026 Oblix. Accountancy Operating System.

Built for UK accountancy practices.