Skip to content
Obligara

About Obligara

Built by the people who ran these programmes

Obligara is a compliance management platform that unifies ISO 9001, ISO 27001, and SOC 2 in one workspace — built by practitioners who ran these programmes, and backed by Valsoft Corporation.

frameworks unified
3

frameworks unified

years in regulated software
30+

years in regulated software

records human-signed
100%

records human-signed

Our origin

Built inside a regulated business, not alongside one

Obligara was created by compliance and security experts with direct experience running QMS and ISMS programmes under real audit scrutiny. The platform was born inside Valsoft Corporation, a technology group that operates across multiple highly regulated industries, and is funded and supported by Valsoft’s infrastructure and institutional knowledge.

The subject matter expertise runs deep. The teams behind our heritage software understand what it means to build for audit trails, evidence integrity, and zero-tolerance for gaps — because they have shipped into exactly those environments for decades.

The expertise behind it

Bold Communications

Over 30 years of mission-critical alarm monitoring software for government, military, banking, utilities, hospitals and police control rooms — where BS and EN standards are operational requirements, not annual exercises.

Innovative Business Software

The same rigour brought to security operations across the Nordics.

GeminiSense

Where that work converged: an integrated incident management platform deployed in some of the most compliance-sensitive environments in Europe.

What we believe

Compliance should work the way the work does

A living system

Compliance should be a living system, not a binder that comes out at audit time.

Evidence once

Evidence gathered for one framework should satisfy another, instead of being collected twice.

AI assists, humans sign

AI should handle the tedious work — gap analysis, mapping and drafting — while humans retain control of every record and every signature.

Our backing

Why Valsoft Corporation

Valsoft Corporation acquires and grows vertical software businesses in industries where accountability and regulatory compliance are operational requirements, not annual exercises — from physical security to life sciences to financial services. Because Valsoft and its subsidiaries face the same audit cycles, evidence requests, and multi-framework overlaps as Obligara’s customers, the problems the product solves were identified from the inside — not by market research.

Obligara exists because Valsoft needed a better tool and decided to build it properly.

Leadership

The people behind Obligara

Practitioners who managed multi-framework compliance programmes before building the software to run them.

Nathan Meldrum

Nathan Meldrum

Technical architect

Nathan Meldrum is the technical architect behind Obligara.

He spent eight years at Bold Communications and GeminiSense, where security monitoring software runs in government, military, banking, and healthcare control rooms across the UK and Europe. He progressed from cloud infrastructure through implementation consulting to leading technical operations across GeminiSense, Bold Communications, Innovative Business Software, and Idhammar Systems — four Valsoft portfolio companies operating under active regulatory and certification requirements.

His hands-on experience spans ISO 27001 implementation, identity and access management, vulnerability management, cloud architecture on Microsoft Azure, and high-availability infrastructure for systems where downtime carries real-world consequences. He has maintained compliance evidence, managed audit processes, and been accountable for the gaps.

Obligara’s core architecture — shared evidence across frameworks, AI-assisted drafting with human sign-off, a single audit trail — reflects the specific shortcomings he encountered in existing tools over those eight years.

Roshan C

Roshan C

Governance, risk & compliance · CISA

Roshan C is a Certified Information Systems Auditor (CISA) with over six years of hands-on experience in information security governance, risk management, and compliance across financial services — one of the most heavily audited sectors in the world.

Before joining the Valsoft Corporation portfolio, Roshan spent four years at AXIS Capital, the global specialty insurance and reinsurance group, as Senior Information Risk Management Governance lead. In that role he developed information security policies and standards, led control gap assessments, managed identity and access controls, and worked directly with external auditors on ISO, SOC 2, NIST, and PCI compliance programmes. Prior to that, he worked as a Senior Information Security Analyst through NTT DATA on a placement at Morgan Stanley, conducting security architecture assessments, developing global security standards, and evaluating emerging technologies against regulatory requirements.

His certifications span the core audit and forensics disciplines: CISA, Certified Cyber Forensics Associate (CFA), and Ethical Hacking Associate (EHA), alongside postgraduate training in Cyber Security and Computer Forensics from Lambton College — an EC-Council accredited institution — covering ISO 27001, NIST 800-53, penetration testing, and legal and regulatory compliance. He holds a Bachelor’s degree in Computer Science from Bangalore University.

Roshan brings to Obligara the exact profile the platform was built to serve: someone who has sat across the table from external auditors at a global financial institution, managed multi-framework compliance programmes in production, and knows precisely where the gaps between frameworks, spreadsheets, and audit reality live.

Marc Cooke

Marc Cooke

Portfolio Manager, Valsoft Corporation

Marc Cooke is Portfolio Manager at Valsoft Corporation and Managing Director across GeminiSense, Bold Communications, and Innovative Business Software — the three companies whose teams and operational experience gave rise to Obligara.

Across his current portfolio, he oversees software businesses serving NHS emergency services, FTSE 100 companies, police forces, airports, oil traders, and global manufacturing operations — environments where compliance is not a growth initiative but an operating condition. That breadth, spanning physical security, financial services, energy trading, and industrial operations, means Marc understands what compliance pressure looks like at the portfolio level: multiple frameworks, multiple jurisdictions, and the ongoing cost of managing them without the right infrastructure.

Before Valsoft, Marc spent two years as Group Sales Director and Director of National Accounts at Chubb Fire & Security — one of the world’s oldest and most regulated security businesses, founded in 1818 — and seven years as Global Operations Director at Electrosonic, managing complex technology deployments across the US, UK, UAE, and China.

The case for Obligara is, in part, a case Marc has been living across a dozen businesses for the last four years.

Joe Gibson

Joe Gibson

Reliability & operational compliance

Joe Gibson’s understanding of compliance comes from the operational end — the manufacturing floors, offshore platforms, and industrial facilities where equipment safety governance, HSE regulations, and reliability-centred maintenance are enforced conditions, not annual reviews.

His career spans over a decade selling and implementing reliability and maintenance solutions into some of the most regulated industrial environments in the UK and Northern Europe. At Fluke Reliability, a global leader in predictive maintenance and asset reliability technology, he progressed from Regional Sales Manager to Director across Northern Europe and Central and Eastern Europe — working with manufacturers, utilities, and heavy industry clients for whom asset compliance and operational governance are inseparable from production continuity. Before that, he spent five years at FUCHS Lubricants and nearly three at Kluthe UK in industrial sales roles with the same operational focus. He holds BINDT CAT 1 & 2 certifications in Oil Analysis and Vibration Analysis and studied Mechanical Engineering Systems at The Open University.

Kyle Purchase

Kyle Purchase

AI Solutions, Valsoft Corporation

Kyle Purchase leads AI Solutions across Valsoft Corporation’s portfolio.

Before joining Valsoft, Kyle founded Mountain AI and spent several years as a business operations consultant, working with companies to identify what was broken, rebuild the underlying processes, and implement AI systems that changed how the business actually operated. His approach to AI is problem-first, not technology-first.

That distinction is built into Obligara’s AI layer. The gap analysis, cross-walk mapping, and draft generation are handled by AI because they are tedious, time-consuming, and do not require human judgment.

That same thinking shapes how Obligara operates as a business. Compliance software companies carry significant internal compliance overhead of their own — across a portfolio as large as Valsoft’s, the ability to identify where AI reduces that burden and where it introduces risk is not a nice-to-have. It’s what keeps the product credible.

FAQ

Frequently asked questions

Last updated: June 2026

See it on your own frameworks

A 30-minute walkthrough on your QMS, ISMS or SOC 2 scope — built by a team that has been on your side of the audit table.