Find your gaps free. Pay to prove it.

One product, two proofs: phishing-resistant identity and a hardened software supply chain. Self-serve up to Business; Enterprise is a conversation.

Free

Find your gaps

$0 /mo

  • Connect one provider
  • On-demand scans
  • Full remediation dashboard — what's wrong & how to fix it
  • Release provenance checks for your published packages
Scan free
Most popular

Pro

Prove it

$149 /mo

  • Everything in Free
  • All providers — identity + supply chain
  • Continuous weekly monitoring + drift alerts
  • Public trust page + verification badges
  • One organization
Start Pro

Business

Prove it across the org

$499 /mo

  • Everything in Pro
  • Multiple domains, orgs & registries
  • Slack alerts + trend history
  • Remediation tracking, up to 10 seats
  • Daily scan cadence
Start Business

Enterprise

Auto-answer the security review

Custom

  • Everything in Business
  • SSO / SAML + private trust center
  • Security-questionnaire automation (live proof, not PDFs)
  • REST API + extended audit retention
  • Priority support
Talk to us

Prices in USD. Cancel anytime. See exactly what each check verifies in our methodology.

Questions

What does PostureProof actually verify?

Two things attackers exploit most: your identity setup (phishing-resistant MFA, no password-only bypass, minimal admins) and your software supply chain (org-wide 2FA, branch protection, locked-down CI tokens, cryptographic build provenance on published releases). Every check reads a specific field from a provider's own API — all of them are listed, with their data sources, in our methodology.

Which providers are supported?

Live today: Google Workspace (read-only OAuth), GitHub organizations (read-only GitHub App), and release provenance for packages you publish to npm, PyPI, or crates.io (read from public registry data — no connection needed). Microsoft 365 and Okta are not available yet. You connect what you have; your score reflects only what we could actually verify. Full detail in our methodology.

What data do you store?

Only aggregated pass/fail results and counts — never raw configuration or user data. Provider data is processed in memory and discarded; only the verification result persists.

Does the public page expose our weaknesses?

No. The public page shows only your overall verified / in-progress state and score. Which specific control failed is visible only to you in the dashboard — a public failure list would be an attacker's to-do list.

How does Enterprise work — is there a sales gauntlet?

No SDR chain, no forced demos. Tell us what you need (SSO, multiple orgs, questionnaire automation, API) and we'll get you set up. Pricing is custom because scope is; the product is the same one you can already try free.

Can I cancel anytime?

Yes — self-serve from your dashboard. Disconnecting a provider deletes its stored tokens immediately; your verification history stays for your records.