PosturaNet Trust Center
We hold our platform to the highest cryptographic and operational security standards, helping you comply with SOC 2, ISO 27001, and CIS benchmarks.
Least Privilege, Scoped Write Access
PosturaNet connects via a cross-account IAM role scoped to the specific read and remediation actions each detection rule requires — never broad admin access. Every write action is approval-gated for medium/high/critical findings and logged before it runs.
Data Encryption & Privacy
All scanned configuration metadata is encrypted in transit using TLS 1.3 and at rest with AES-256 keys. We do not inspect or store any customer application database records.
Formal Safety Checks Before Every Fix
Every automated fix passes a dry-run and a Z3 SMT-backed safety check — today covering network-reachability and IAM wildcard-permission invariants — before it can execute, with a one-click signed rollback if anything looks wrong.
Signed Audit Trail
Remediation actions and rollback states are cryptographically signed (ECDSA via KMS) and logged to an append-only audit trail, mapped to CIS, SOC 2, and NIST controls for your own compliance evidence.
Compliance Framework Alignments
PosturaNet is architected to automatically enforce and map assets to core industry regulatory frameworks:
Security, Confidentiality & Availability
Identity, Network, Logging & Monitoring
Access Control & Risk Assessment
Need custom security questionnaires or SLA policies?
Design partners receive dedicated compliance enclaves and customized questionnaires matching corporate procurement requirements.