Software depends on people.

Know what protects the people who ship it.

Your dependency graph ends in accounts, repositories, and release pipelines. PostureProof makes their security evidence visible—and the unknowns explicit.

Public lookup is free. No installation. No code execution.

The evidence chainScope matters
01

Identity

Who protects the accounts?

02

Source & CI

Which controls govern release changes?

03

Package release

What does the registry actually report?

04

Your dependency

What evidence can your team rely on?

Each link needs evidence. A repository URL is a hint. An unknown identity stays unknown.

For publishers

We verify the controls.
You keep control.

Connect Google Workspace and GitHub with read-only access. Inspect findings privately, then choose whether to publish a dated assessment. Payment never determines a passing result.

Create an assessment →

For dependency consumers

Turn missing evidence
into a review workflow.

Upload a lockfile. Inspect exact releases, compare registry integrity metadata, and record follow-up decisions. Export the evidence for your team's next review.

Review dependencies →

A narrower claim. A more useful proof.

Read from the source

Provider APIs supply the observations. We distinguish reported settings from validated release origin.

Dated and scoped

Every published assessment names its providers, observation date and expiration. Incomplete evidence stays incomplete.

Private by choice

Account-level findings stay in your workspace. Public assessments are opt-in. Missing verification is not an accusation.

Read the verification standard →