PostureAI

Security at PostureAI

Security is not a marketing page — it's a product requirement for healthcare software. Here is what we actually do.

Encryption

AES-256 at rest with AWS KMS-managed keys (RDS and S3). TLS 1.2+ in transit.

Access control

Role-based permissions with least privilege. MFA available on all accounts. 15-minute idle session timeouts. Production access restricted to on-call staff and logged.

Monitoring

All PHI access is logged in an append-only, tamper-evident audit trail retained for six years.

Infrastructure

AWS US regions. VPC isolation with private subnets for the database and cache. Automated daily encrypted backups with point-in-time recovery.

Secrets

All secrets live in AWS Secrets Manager with KMS encryption. No secret ever stored in source, environment files, or logs. Rotation schedules per category.

Incident response

Documented SEV levels with defined response owners. HIPAA breach notification in under 60 days. Post-incident reviews shared with affected customers.

Responsible disclosure

If you find a vulnerability, email security@posturegrade.com. We acknowledge reports within one business day, triage within three, and fix critical issues without a negotiated timeline.

We do not run a paid bounty program yet, but we gratefully credit researchers who report in good faith and allow us time to fix before public disclosure.

Certifications and audits

HIPAA-aligned from day one. SOC 2 certification and independent penetration testing are on our compliance roadmap.

Need our security whitepaper?