Security and data handling

What SecurITPosture keeps, what it never sees, and where it runs

A compliance tool has to answer for its own posture before it can help with yours. This page states ours plainly and is updated whenever the answer changes.

01

Where the platform runs

To addHosting region and provider (AWS commercial, AWS GovCloud, or another), impact level targeted (IL2, IL4, IL5), and whether customer data ever leaves the United States.

02

Our own authorizations

To addFedRAMP status for SecurITPosture itself: authorized, in process with a named agency sponsor, or not pursuing. SOC 2 Type 1 or Type 2 status and the audit period. State it plainly, including if the answer is not yet.

03

How we reach your cloud account

SecurITPosture connects to AWS through a cross account IAM role that you create and that the platform assumes with STS AssumeRole. No access keys, secrets, or long lived credentials are entered into or stored by the platform. Only encrypted connection metadata is kept: the account id, the role ARN, the regions you selected, and the scan schedule. Removing the integration deletes that metadata and keeps the audit log of the connection.

To addThe exact permission set the role needs, as a downloadable policy document, and a list of what is read (configuration, inventory, findings) and what is never read (object contents, database rows, secrets).

04

Residency, retention, and deletion

Audit history is retained after the record it describes is removed, so an assessor can always reconstruct who changed what and when. Every mutation of a compliance record writes an audit event with the actor, the action, the target, and a UTC timestamp.

To addData residency commitment, retention period for customer package data after a contract ends, the deletion procedure and its confirmation, and backup retention.

05

Who at Vesta can see customer data

To addWhich roles at Vesta can access customer package data, under what approval, whether access is logged and reviewed, and how support access is granted and revoked.

06

Reporting a vulnerability

If you believe you have found a security issue in SecurITPosture, write to security@vestacybersolutions.com. We acknowledge reports within two business days, tell you when the fix ships, and credit you if you wish. The same details are published in machine readable form at /.well-known/security.txt.

Please test only against accounts and data you own, do not access or alter other customers' data, and do not run denial of service or social engineering. We will not pursue researchers who follow these rules and report in good faith. Fix windows: critical within 24 hours, high within 7 days, medium within 30 days.