Continuously verified — not a point-in-time PDF

Prove you're hardened against how attacks actually happen

Two vectors cause most breaches today: phishing and software supply-chain compromise. PostureProof connects read-only to your identity provider, code hub, and package registries, and verifies the specific settings that stop them — nothing self-reported, nothing we can't read from the source.

PostureProof

Phishing-Resistant

PostureProof

Supply-Chain Hardened

Your shareable proof — verified fresh, on a schedule. See exactly what we check →

Attackers don't pick locks. They log in — or poison what you install.

The playbook is public and boring. Two doors account for most real-world compromise. PostureProof checks that both are shut.

Vector 1 · Identity

Phishing & credential theft

Stolen passwords, MFA-fatigue, session hijacking. If an attacker can log in as your admin, they own the domain — no exploit required.

80%+

of breaches involve stolen or weak credentials (Verizon DBIR).

Vector 2 · Supply chain

Poisoned dependencies

A compromised maintainer or an unhardened repo ships malicious code to everyone downstream. One weak token, and your releases become the attack.

Rising fast

npm, PyPI and crates worms (Shai-Hulud, s1ngularity, event-stream) all rode the same chain.

Three connections. One proof.

Every control below is read from a provider's own API — the exact field is published in our methodology. Nothing is self-attested.

Connect what you have; your score reflects only what we could actually verify.

Identity

Google Workspace

  • Phishing-resistant MFA enforced for admins and users
  • Strong password policy
  • Minimal super-admins
  • Legacy password-only access disabled

Live — connect and scan today

Microsoft 365 and Okta are not available yet.

Code hub

GitHub organization

  • Org-wide 2FA required for every member
  • Branch protection with required reviews
  • Read-only default CI tokens
  • Secret scanning and push protection

Checks built — org connect rolling out

Ask us for early access.

Releases

npm · PyPI · crates.io

  • Latest release carries cryptographic build provenance
  • Published from CI, not a laptop with a long-lived token
  • Provenance traced back to a repo in your verified org

Live — verified from public registry data

Sigstore attestations · PEP 740 · Trusted Publishing.

A PDF says you were compliant once. A PostureProof badge says you're hardened right now.

Trust centers host documents. PostureProof re-checks the actual settings on a schedule and flips your badge the moment something drifts. The date is on the badge — anyone can see how fresh it is.

Live

Verified from your provider's own APIs, re-run on a schedule — not self-attested.

Binary

MFA is on or off. 2FA is required or it isn't. No judgment calls, no consultants.

Private where it counts

The public page shows verified/in-progress only. Which control failed stays with you — never an attacker's roadmap.

Proof in three steps

1

Connect

One-click, read-only access to your identity provider, and list the packages you publish. No config files, no domain-wide delegation.

2

Scan & fix

See exactly what's wrong and how to fix it, ranked by impact — with deep links straight to the setting. Re-scanned continuously.

3

Prove it

Earn your badges and a public trust page. Embed them where customers and downstream users can see them.

Find your gaps free. Pay to prove it.

Self-serve up to Business. Enterprise is a conversation, not a sales gauntlet.

Free

Find your gaps

$0 /mo

  • Connect one provider
  • On-demand scans
  • Full remediation dashboard — what's wrong & how to fix it
  • Release provenance checks for your published packages
Scan free
Most popular

Pro

Prove it

$149 /mo

  • Everything in Free
  • All providers — identity + supply chain
  • Continuous weekly monitoring + drift alerts
  • Public trust page + verification badges
  • One organization
Start Pro

Business

Prove it across the org

$499 /mo

  • Everything in Pro
  • Multiple domains, orgs & registries
  • Slack alerts + trend history
  • Remediation tracking, up to 10 seats
  • Daily scan cadence
Start Business

Enterprise

Auto-answer the security review

Custom

  • Everything in Business
  • SSO / SAML + private trust center
  • Security-questionnaire automation (live proof, not PDFs)
  • REST API + extended audit retention
  • Priority support
Talk to us

Prices in USD. Cancel anytime. See exactly what each check verifies in our methodology.

Would you survive how you'll actually get attacked?

Connect read-only. See your phishing and supply-chain gaps in 60 seconds. Know for sure.

Find your gaps — free