Privacy Policy

Last updated September 18, 2026

Summary

PostureProof verifies whether your organization has hardened its identity and software-supply-chain settings. We connect to your providers with read-only access, evaluate a fixed set of security controls, and store aggregated provider-check results. We also store account information and, when you use dependency reviews, extracted dependency metadata, public observations and your review notes. We do not retain the original uploaded lockfile.

What we access

When you connect a provider, you grant scoped, read-only access:

  • Google Workspace — read-only directory, role, and admin-reports data used solely to evaluate MFA enrollment, password policy, admin counts, and legacy-access settings.
  • GitHub accounts and organizations — read-only account, collaborator, repository and release-control observations. When authorized, Actions access supplies deployment-environment settings and Contents access supplies workflow configuration at a specific commit. GitHub's Contents permission permits reading files in installed repositories; our repository safeguard checks read bounded workflow files, not the full source tree.

We request the minimum scopes required and never request write access.

What we store

  • Aggregated check results: control outcomes and counts (e.g. "10 of 17 users have 2SV"). Legacy assessments may retain internal scores; scores are not public verification criteria.
  • Private account and release-access evidence: account and repository identifiers, observed roles, administrator authentication indicators, deploy-key metadata without key material, branch and environment settings, and workflow observation labels and locations. We do not retain the raw workflow files used by repository safeguard checks.
  • Your sign-in identity, name, email, workspace membership, organization identifiers, subscriptions and verification history.
  • Extracted dependency names, versions, integrity values, public registry observations and review notes for saved inventories. Avoid placing secrets in review notes.
  • An encrypted OAuth refresh token (for continuous monitoring), which you can revoke at any time.

Provider responses are processed to extract the observations described above. Checks do not request secret values or execute repository workflows. Public registry observations used for lookup and dependency reviews may be cached and retained with the review.

Service providers

We use a small number of subprocessors to operate the service: Cloudflare (hosting and database), Stripe (payments), and a transactional email provider for account notifications. We do not sell your data or share it for advertising.

Public verification pages

If a workspace owner chooses publication, the assessment exposes provider scope, aggregate control outcomes, observation dates and expiration. Publication does not require payment. Individual account findings and private inventories are not published.

Data retention & deletion

You can disconnect a provider at any time from your dashboard, which removes its stored credentials from our workspace connection. You may also revoke the application through your provider. You may request deletion of your verification history and account data by contacting us.

Google API disclosure

PostureProof's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Workspace data only to provide the security-verification features described here, never for advertising, and never sold or transferred to third parties except as required to operate the service or comply with law.

Contact

Questions about this policy or your data: social@vulnu.com.