Privacy Policy
Last updated August 24, 2026
Summary
PostureProof verifies whether your organization has hardened its identity and software-supply-chain settings. We connect to your providers with read-only access, evaluate a fixed set of security controls, and store only the aggregated result — pass/fail states and counts. We do not store your users' personal data, raw configuration, or the contents of your systems.
What we access
When you connect a provider, you grant scoped, read-only access:
- Google Workspace — read-only directory, role, and admin-reports data used solely to evaluate MFA enrollment, password policy, admin counts, and legacy-access settings.
- GitHub organizations — read-only organization and repository security settings (2FA requirement, branch protection, workflow permissions, secret scanning).
We request the minimum scopes required and never request write access.
What we store
- Aggregated check results: pass/fail, a numeric score, and counts (e.g. "10 of 17 users have 2SV"). No individual user identities.
- Your organization's domain, plan, and verification history.
- An encrypted OAuth refresh token (for continuous monitoring), which you can revoke at any time.
Provider data is processed in memory to compute results and is not otherwise retained.
Service providers
We use a small number of subprocessors to operate the service: Cloudflare (hosting and database), Stripe (payments), and Resend (transactional email). We do not sell your data or share it for advertising.
Public verification pages
If you subscribe to a paid plan and choose to publish a verification badge, your overall verification state and score become public on your verification page. Individual control outcomes are never made public.
Data retention & deletion
You can disconnect a provider at any time from your dashboard, which immediately deletes the stored access token. You may request deletion of your verification history and account data by contacting us.
Google API disclosure
PostureProof's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Workspace data only to provide the security-verification features described here, never for advertising, and never sold or transferred to third parties except as required to operate the service or comply with law.
Contact
Questions about this policy or your data: social@vulnu.com.