Security at PostureAI
Security is not a marketing page — it's a product requirement for healthcare software. Here is what we actually do.
Encryption
AES-256 at rest with AWS KMS-managed keys (RDS and S3). TLS 1.2+ in transit.
Access control
Role-based permissions with least privilege. MFA available on all accounts. 15-minute idle session timeouts. Production access restricted to on-call staff and logged.
Monitoring
All PHI access is logged in an append-only, tamper-evident audit trail retained for six years.
Infrastructure
AWS US regions. VPC isolation with private subnets for the database and cache. Automated daily encrypted backups with point-in-time recovery.
Secrets
All secrets live in AWS Secrets Manager with KMS encryption. No secret ever stored in source, environment files, or logs. Rotation schedules per category.
Incident response
Documented SEV levels with defined response owners. HIPAA breach notification in under 60 days. Post-incident reviews shared with affected customers.
Responsible disclosure
If you find a vulnerability, email security@posturegrade.com. We acknowledge reports within one business day, triage within three, and fix critical issues without a negotiated timeline.
We do not run a paid bounty program yet, but we gratefully credit researchers who report in good faith and allow us time to fix before public disclosure.
Certifications and audits
HIPAA-aligned from day one. SOC 2 certification and independent penetration testing are on our compliance roadmap.