Legal
Security
Last updated: September 29, 2026 · Effective for securityposture.dev
1. Our security posture
SecurityPosture is built to help you understand external exposure — and we hold ourselves to clear product-security practices while we grow. This page describes how we think about protecting customer data. It is not a claim of SOC 2, ISO, or other certifications we have not earned.
2. What we analyze
- Passive discovery of publicly observable assets and signals
- Configuration and posture checks that do not require credentials for basic scans
- Evidence-backed findings with AI explanations — not invented observations
We do not perform credential harvesting, destructive testing, or unauthorized exploitation as part of the core product. See also what we don’t do.
3. Data protection practices
- Encryption in transit (TLS) for web and API traffic
- Access controls scoped to workspaces and authenticated users
- Scan isolation so one customer’s analysis does not bleed into another
- Retention controls and deletion requests via support
- Audit-oriented logging of sensitive account actions as features ship
4. Infrastructure
Application hosting is planned on Vercel with Supabase for database/auth and AWS for supporting cloud services. Specific providers and regions may evolve; material changes will be reflected here and in our Privacy Policy.
5. Customer responsibilities
- Only submit domains you own or are authorized to assess
- Protect your account credentials and invite only trusted teammates
- Treat findings as decision support and validate critical changes before production remediation
6. Reporting a vulnerability
If you believe you’ve found a security issue in SecurityPosture itself, please follow our responsible disclosure process. Contact: security@securityposture.dev.