Prove you're hardened against how attacks actually happen
Two vectors cause most breaches today: phishing and software supply-chain compromise. PostureProof connects read-only to your identity provider, code hub, and package registries, and verifies the specific settings that stop them — nothing self-reported, nothing we can't read from the source.
PostureProof
Phishing-Resistant
PostureProof
Supply-Chain Hardened
Your shareable proof — verified fresh, on a schedule. See exactly what we check →
Attackers don't pick locks. They log in — or poison what you install.
The playbook is public and boring. Two doors account for most real-world compromise. PostureProof checks that both are shut.
Phishing & credential theft
Stolen passwords, MFA-fatigue, session hijacking. If an attacker can log in as your admin, they own the domain — no exploit required.
of breaches involve stolen or weak credentials (Verizon DBIR).
Poisoned dependencies
A compromised maintainer or an unhardened repo ships malicious code to everyone downstream. One weak token, and your releases become the attack.
npm, PyPI and crates worms (Shai-Hulud, s1ngularity, event-stream) all rode the same chain.
Three connections. One proof.
Every control below is read from a provider's own API — the exact field is published in our methodology. Nothing is self-attested.
Connect what you have; your score reflects only what we could actually verify.
Identity
Google Workspace
- ✓ Phishing-resistant MFA enforced for admins and users
- ✓ Strong password policy
- ✓ Minimal super-admins
- ✓ Legacy password-only access disabled
Live — connect and scan today
Microsoft 365 and Okta are not available yet.
Code hub
GitHub organization
- ✓ Org-wide 2FA required for every member
- ✓ Branch protection with required reviews
- ✓ Read-only default CI tokens
- ✓ Secret scanning and push protection
Checks built — org connect rolling out
Ask us for early access.
Releases
npm · PyPI · crates.io
- ✓ Latest release carries cryptographic build provenance
- ✓ Published from CI, not a laptop with a long-lived token
- ✓ Provenance traced back to a repo in your verified org
Live — verified from public registry data
Sigstore attestations · PEP 740 · Trusted Publishing.
A PDF says you were compliant once. A PostureProof badge says you're hardened right now.
Trust centers host documents. PostureProof re-checks the actual settings on a schedule and flips your badge the moment something drifts. The date is on the badge — anyone can see how fresh it is.
Verified from your provider's own APIs, re-run on a schedule — not self-attested.
MFA is on or off. 2FA is required or it isn't. No judgment calls, no consultants.
The public page shows verified/in-progress only. Which control failed stays with you — never an attacker's roadmap.
Proof in three steps
Connect
One-click, read-only access to your identity provider, and list the packages you publish. No config files, no domain-wide delegation.
Scan & fix
See exactly what's wrong and how to fix it, ranked by impact — with deep links straight to the setting. Re-scanned continuously.
Prove it
Earn your badges and a public trust page. Embed them where customers and downstream users can see them.
Find your gaps free. Pay to prove it.
Self-serve up to Business. Enterprise is a conversation, not a sales gauntlet.
Free
Find your gaps
$0 /mo
- Connect one provider
- On-demand scans
- Full remediation dashboard — what's wrong & how to fix it
- Release provenance checks for your published packages
Pro
Prove it
$149 /mo
- Everything in Free
- All providers — identity + supply chain
- Continuous weekly monitoring + drift alerts
- Public trust page + verification badges
- One organization
Business
Prove it across the org
$499 /mo
- Everything in Pro
- Multiple domains, orgs & registries
- Slack alerts + trend history
- Remediation tracking, up to 10 seats
- Daily scan cadence
Enterprise
Auto-answer the security review
Custom
- Everything in Business
- SSO / SAML + private trust center
- Security-questionnaire automation (live proof, not PDFs)
- REST API + extended audit retention
- Priority support
Prices in USD. Cancel anytime. See exactly what each check verifies in our methodology.
Would you survive how you'll actually get attacked?
Connect read-only. See your phishing and supply-chain gaps in 60 seconds. Know for sure.
Find your gaps — free