Legal

Security

Last updated: September 29, 2026 · Effective for securityposture.dev

1. Our security posture

SecurityPosture is built to help you understand external exposure — and we hold ourselves to clear product-security practices while we grow. This page describes how we think about protecting customer data. It is not a claim of SOC 2, ISO, or other certifications we have not earned.

2. What we analyze

  • Passive discovery of publicly observable assets and signals
  • Configuration and posture checks that do not require credentials for basic scans
  • Evidence-backed findings with AI explanations — not invented observations

We do not perform credential harvesting, destructive testing, or unauthorized exploitation as part of the core product. See also what we don’t do.

3. Data protection practices

  • Encryption in transit (TLS) for web and API traffic
  • Access controls scoped to workspaces and authenticated users
  • Scan isolation so one customer’s analysis does not bleed into another
  • Retention controls and deletion requests via support
  • Audit-oriented logging of sensitive account actions as features ship

4. Infrastructure

Application hosting is planned on Vercel with Supabase for database/auth and AWS for supporting cloud services. Specific providers and regions may evolve; material changes will be reflected here and in our Privacy Policy.

5. Customer responsibilities

  • Only submit domains you own or are authorized to assess
  • Protect your account credentials and invite only trusted teammates
  • Treat findings as decision support and validate critical changes before production remediation

6. Reporting a vulnerability

If you believe you’ve found a security issue in SecurityPosture itself, please follow our responsible disclosure process. Contact: security@securityposture.dev.

Responsible disclosure · Security · Scan a domain · Home