Security & Compliance

PosturaNet Trust Center

We maintain the highest cryptographic and operational security standards to help you meet SOC 2, ISO 27001, and CIS benchmark compliance requirements.

Trust Center launch coming with GA. This page documents our active security practices, certifications in progress, penetration testing program, and data processing commitments.

Least Privilege, Scoped Write Access

PosturaNet connects via a cross-account IAM role scoped to the specific read and remediation actions each detection rule requires — never broad admin access. Every write action is approval-gated for medium/high/critical findings and logged before it runs.

Data Encryption & Privacy

All scanned configuration metadata is encrypted in transit using TLS 1.3 and at rest with AES-256 keys. We do not inspect or store any customer application database records.

Formal Safety Checks Before Every Fix

Every automated fix passes a dry-run and a Z3 SMT-backed safety check — today covering network-reachability and IAM wildcard-permission invariants — before it can execute, with a one-click signed rollback if anything looks wrong.

Signed Audit Trail

Remediation actions and rollback states are cryptographically signed (ECDSA via KMS) and logged to an append-only audit trail, mapped to CIS, SOC 2, and NIST controls for your own compliance evidence.

Compliance Framework Alignments

PosturaNet is architected to automatically enforce and map assets to core industry regulatory frameworks:

SOC 2 Type II

Security, Confidentiality & Availability

CIS AWS Foundations

Identity, Network, Logging & Monitoring

NIST SP 800-53

Access Control & Risk Assessment

Need custom security questionnaires or SLA policies?

Design partners receive dedicated compliance enclaves and customized questionnaires matching corporate procurement requirements.