Obsidian
Notes stay local Markdown files you own, with backlinks and plugins covering almost any workflow.
What it does
| Primary use case | Obsidian centers on personal note-taking, knowledge management, and building interconnected idea networks through backlinks. |
|---|---|
| Data storage and ownership | Obsidian stores notes as local Markdown files on your device, giving you direct file-system ownership and control. |
| Collaboration model | Obsidian is primarily single-user; team collaboration requires third-party sync solutions or the paid Obsidian Sync service. |
| Keyboard and speed focus | Obsidian supports keyboard shortcuts and is fast for local files, but its speed focus is on note retrieval rather than issue triage. |
| Extensibility | Obsidian provides a plugin marketplace covering diverse workflows—task management, calendars, diagrams, and more—maintained by the community. |
Pick Obsidian if
- You want full ownership of your notes as local Markdown files, independent of any vendor's servers.
- Personal knowledge management, backlinks, and graph-based idea exploration match your workflow.
- You value extensive customization through community plugins and themes.
- You work solo or need only occasional, manual sharing of notes rather than live team collaboration.
- You need a dedicated note-taking system with backlinks and graph views for knowledge management.
- You want full ownership of your notes as local Markdown files without cloud dependencies.
Compare
Security headers: C, 65 out of 100
Number 47 of 95 in the ranking. Missing 3 of the 9 headers we check.
Below the B minimum (70/100) in our RFP clause. A buyer using it would ask for a dated fix for each missing header.
With these headers missing, obsidian.md is more exposed to malicious JavaScript, redirected forms, hijacked payments and clickjacking.
Missing 3
-
Content-Security-Policy 0 of 25
Tells the browser which scripts may run on the page, where its forms may submit, and where it may send data.
Without it: This is the main defence against malicious JavaScript. If an attacker gets any script onto the page (through a bug, a compromised analytics tag, chat widget or ad, or a poisoned package), the browser runs it with the signed-in user's full access. It can capture what they type, quietly point a sign-in or checkout form at the attacker's server, and skim card numbers as they are entered. A strict policy blocks scripts it does not list, and its form-action and connect-src rules leave stolen data nowhere to go.
-
Cross-Origin-Opener-Policy 0 of 5
Cuts the link between the product's window and windows opened by, or opening, other sites.
Without it: A page that opens the product keeps a handle on its window and can later redirect it to a look-alike sign-in or payment page (tab-nabbing) while the user thinks they are still on the real site. It is also part of the isolation browsers need to defend against Spectre-style attacks.
-
Cross-Origin-Resource-Policy 0 of 5
Tells browsers which sites may load this site's resources.
Without it: Other sites can pull the product's responses into their own pages, which makes side-channel leaks of what a signed-in user can see easier.
Sent 6
-
Strict-Transport-Security 20 of 20
max-age=7776000
-
X-Content-Type-Options 10 of 10
nosniff
-
Frame protection 10 of 10
SAMEORIGIN
-
Referrer-Policy 10 of 10
strict-origin-when-cross-origin
-
Permissions-Policy 10 of 10
microphone=()
-
No version disclosure 5 of 5
server: cloudflare