Security and data handling
What SecurITPosture keeps, what it never sees, and where it runs
A compliance tool has to answer for its own posture before it can help with yours. This page states ours plainly and is updated whenever the answer changes.
01
Where the platform runs
02
Our own authorizations
03
How we reach your cloud account
SecurITPosture connects to AWS through a cross account IAM role that you create and that the platform assumes with STS AssumeRole. No access keys, secrets, or long lived credentials are entered into or stored by the platform. Only encrypted connection metadata is kept: the account id, the role ARN, the regions you selected, and the scan schedule. Removing the integration deletes that metadata and keeps the audit log of the connection.
04
Residency, retention, and deletion
Audit history is retained after the record it describes is removed, so an assessor can always reconstruct who changed what and when. Every mutation of a compliance record writes an audit event with the actor, the action, the target, and a UTC timestamp.
05
Who at Vesta can see customer data
06
Reporting a vulnerability
If you believe you have found a security issue in SecurITPosture, write to security@vestacybersolutions.com. We acknowledge reports within two business days, tell you when the fix ships, and credit you if you wish. The same details are published in machine readable form at /.well-known/security.txt.
Please test only against accounts and data you own, do not access or alter other customers' data, and do not run denial of service or social engineering. We will not pursue researchers who follow these rules and report in good faith. Fix windows: critical within 24 hours, high within 7 days, medium within 30 days.