Find your gaps free. Pay to prove it.
One product, two proofs: phishing-resistant identity and a hardened software supply chain. Self-serve up to Business; Enterprise is a conversation.
Free
Find your gaps
$0 /mo
- Connect one provider
- On-demand scans
- Full remediation dashboard — what's wrong & how to fix it
- Release provenance checks for your published packages
Pro
Prove it
$149 /mo
- Everything in Free
- All providers — identity + supply chain
- Continuous weekly monitoring + drift alerts
- Public trust page + verification badges
- One organization
Business
Prove it across the org
$499 /mo
- Everything in Pro
- Multiple domains, orgs & registries
- Slack alerts + trend history
- Remediation tracking, up to 10 seats
- Daily scan cadence
Enterprise
Auto-answer the security review
Custom
- Everything in Business
- SSO / SAML + private trust center
- Security-questionnaire automation (live proof, not PDFs)
- REST API + extended audit retention
- Priority support
Workflow Audit Coming soon
Add-on. Everything above reads org-level policy. This reads the workflows themselves — untrusted input interpolated into run: steps, pull_request_target checking out fork code, secrets: inherit — with findings down to the file and line.
Requires read access to your source, so it's a separate, explicit permission upgrade — never a silent scope change.
Prices in USD. Cancel anytime. See exactly what each check verifies in our methodology.
Questions
What does PostureProof actually verify?
Two things attackers exploit most: your identity setup (phishing-resistant MFA, no password-only bypass, minimal admins) and your software supply chain (org-wide 2FA, branch protection, locked-down CI tokens, cryptographic build provenance on published releases). Every check reads a specific field from a provider's own API — all of them are listed, with their data sources, in our methodology.
Which providers are supported?
Live today: Google Workspace (read-only OAuth), GitHub organizations (read-only GitHub App), and release provenance for packages you publish to npm, PyPI, or crates.io (read from public registry data — no connection needed). Microsoft 365 and Okta are not available yet. You connect what you have; your score reflects only what we could actually verify. Full detail in our methodology.
What data do you store?
Only aggregated pass/fail results and counts — never raw configuration or user data. Provider data is processed in memory and discarded; only the verification result persists.
Does the public page expose our weaknesses?
No. The public page shows only your overall verified / in-progress state and score. Which specific control failed is visible only to you in the dashboard — a public failure list would be an attacker's to-do list.
How does Enterprise work — is there a sales gauntlet?
No SDR chain, no forced demos. Tell us what you need (SSO, multiple orgs, questionnaire automation, API) and we'll get you set up. Pricing is custom because scope is; the product is the same one you can already try free.
Can I cancel anytime?
Yes — self-serve from your dashboard. Disconnecting a provider deletes its stored tokens immediately; your verification history stays for your records.