Software depends on people.
Know what protects the people who ship it.
Your dependency graph ends in accounts, repositories, and release pipelines. PostureProof makes their security evidence visible—and the unknowns explicit.
Public lookup is free. No installation. No code execution.
Identity
Who protects the accounts?
Source & CI
Which controls govern release changes?
Package release
What does the registry actually report?
Your dependency
What evidence can your team rely on?
Each link needs evidence. A repository URL is a hint. An unknown identity stays unknown.
For publishers
We verify the controls.
You keep control.
Connect Google Workspace and GitHub with read-only access. Inspect findings privately, then choose whether to publish a dated assessment. Payment never determines a passing result.
Create an assessment →For dependency consumers
Turn missing evidence
into a review workflow.
Upload a lockfile. Inspect exact releases, compare registry integrity metadata, and record follow-up decisions. Export the evidence for your team's next review.
Review dependencies →A narrower claim. A more useful proof.
Read from the source
Provider APIs supply the observations. We distinguish reported settings from validated release origin.
Dated and scoped
Every published assessment names its providers, observation date and expiration. Incomplete evidence stays incomplete.
Private by choice
Account-level findings stay in your workspace. Public assessments are opt-in. Missing verification is not an accusation.