Privacy Policy

Last updated: October 1, 2026

This Privacy Policy explains how Vicant Solutions LLC, a Florida limited liability company, d/b/a Nubrix Security ("PosturaIQ," "we," "us") collects, uses and protects information in connection with posturaiq.com and the PosturaIQ Service. PosturaIQ is a security product, and we hold our own handling of your data to the same standard.

1. Our role

  • For account and website information (for example, your name and work email), we act as the controller.
  • For Customer Data collected from your Microsoft tenant, we act as a processor or service provider on behalf of your organization, which is the controller. We process it only to provide the Service to your organization. A Data Processing Addendum is available on request at privacy@posturaiq.com.

2. Information we collect

Account information: your name, work email address, organization name, role, Microsoft account identifiers (tenant ID and object ID); PosturaIQ does not store customer passwords, invitation records, and records of your agreement to our terms.

Enquiry information: the contact details you submit through our enquiry, demo and contact forms: your name, business email, company, role, environment size and message, and how you heard about us. We use them only to respond to you and to evaluate and onboard your organization.

Microsoft tenant data (Customer Data): after an administrator grants consent, PosturaIQ reads configuration evidence from your tenant through Microsoft Graph and, where extended access is enabled, through workload-specific Microsoft interfaces. This may include:

  • tenant and organization details, verified domains, and license and subscription information;
  • directory user and group information relevant to security controls, such as display names, user principal names, account status, license assignments, group memberships, and administrative role assignments and eligibility;
  • security policy configuration, such as Conditional Access, authentication methods and security defaults;
  • Microsoft Secure Score and control profiles;
  • configuration for Exchange Online, SharePoint and OneDrive, Teams, Defender, Purview, Power BI and Power Platform.

PosturaIQ reads configuration and metadata. It does not read the contents of email messages, files, chats or documents.

Service activity: assessments, findings, remediation status and notes, validation records, reports, and audit events, such as permission grants, assessment runs, role changes and administrative access.

Technical information: IP address, browser type, device information, and log data needed to operate and secure the Service. We use only cookies that are necessary for sign-in and for operating the Service.

3. How we use information

We use information to:

  • provide, operate and secure the Service;
  • run assessments and generate findings, remediation guidance, validation and reports for your organization;
  • provide AI-assisted explanations and remediation guidance for findings (see Section 4);
  • authenticate users and enforce tenant isolation and plan entitlements;
  • communicate with you about your account, security notices and service changes;
  • respond to enquiries and provide support and expert review;
  • bill for paid plans;
  • comply with legal obligations.

We may use aggregated, de-identified data that cannot identify you, your users or your tenant to improve the Service. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use Customer Data to train artificial intelligence models.

4. AI-assisted features

PosturaIQ Premier and Enterprise plans include an AI assistant that explains individual findings and how to remediate them. It runs only when a user selects an action on a specific finding.

What is sent: the PosturaIQ control catalog entry for that finding and the finding's assessment evidence, which is configuration data such as settings, policy names, rule names and domain names. For licensing questions, the names of your tenant's Microsoft 365 subscriptions are included, and for PowerShell guidance, your tenant's initial onmicrosoft.com domain. The contents of email, files, chats and documents are never sent, because PosturaIQ does not collect them.

Who processes it: Microsoft Azure OpenAI in Microsoft Foundry, under Microsoft's terms, which prohibit Microsoft from using this data to train models. AI requests may be processed in any Azure region where the model is available; the data PosturaIQ stores remains in the United States. PosturaIQ does not use Customer Data to train AI models.

Microsoft abuse monitoring: Microsoft may retain AI prompts and outputs for up to 30 days to detect and prevent abuse, and content flagged by its safety systems may be reviewed by authorized Microsoft personnel.

What PosturaIQ keeps: generated answers and a usage record (user, finding, action, date and usage counts) are stored in Microsoft Azure in the United States for up to 90 days, to return repeat answers quickly, enforce usage limits and review quality, and are then deleted automatically.

AI-generated content may be incomplete or inaccurate. Review it before making changes, as described in our Terms of Service.

5. How we share information

We share information only:

  • with service providers that host or support the Service under confidentiality and data protection obligations (see Section 6);
  • with your organization, since administrators and members can see your organization's data according to their roles;
  • with Microsoft, if you purchase through Microsoft Marketplace, to process your subscription and billing;
  • with an authorized partner, if your organization obtained the Service through that partner and has granted it access to your workspace;
  • when required by law or to protect the rights, safety and security of our users or the Service;
  • in connection with a merger, acquisition or sale of assets, subject to this Policy.

6. Service providers (subprocessors)

  • Microsoft Azure (United States, East US 2) — assessment processing, automation, and secret and key management.
  • Microsoft Azure OpenAI in Microsoft Foundry — AI-assisted features (Premier and Enterprise plans). Requests may be processed in any Azure region where the model is available.
  • Lovable Cloud / Supabase (United States) — application hosting, database, authentication, and transactional email such as verification and invitations.

We will update this list when we add providers.

7. Data location and security

Customer Data is stored and processed in the United States, except that requests to AI-assisted features may be processed in other Azure regions, as described in Section 4. Microsoft credentials, tokens and secrets are held only on the backend, in managed key storage, and never reach the browser. Access to data is scoped to your organization on the server, and security-relevant actions are audited. Data is encrypted in transit and at rest. See posturaiq.com/security for more detail.

8. Retention and deletion

  • Account and Customer Data is retained while your organization's account is active.
  • Disconnecting a tenant removes PosturaIQ's access to that tenant immediately. Previously collected assessment data remains in your workspace until you delete it or close your organization.
  • After a subscription is canceled or expires, or a trial ends, the account enters read-only mode: previously generated Assessment Reports remain available to view and download for 90 days, and other portal features are suspended. Reactivating the subscription restores full access. After 90 days, we delete Customer Data within 30 days, and backup copies within a further 30 days. You can request earlier deletion at privacy@posturaiq.com.
  • Audit records are kept for 12 months for security and accountability.
  • AI assistant answers and usage records are deleted automatically after 90 days.
  • Enquiry records are kept for up to 24 months.
  • We may retain limited records longer where the law requires it, such as billing records.

To request deletion, contact privacy@posturaiq.com.

9. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete or export your personal information, or to object to or restrict certain processing. For Customer Data, please contact your organization's administrator first, since your organization controls that data. We will assist them. To exercise your rights, email privacy@posturaiq.com. We will not discriminate against you for exercising your rights.

10. Children

The Service is intended for businesses and is not directed to anyone under 16. We do not knowingly collect personal information from children.

11. International users

We are based in the United States, and we process data there. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.

12. Changes to this policy

We may update this Privacy Policy. If we make material changes, we will notify account owners by email or in the Service before they take effect. The "Last updated" date shows the current version.

13. Contact

Vicant Solutions LLC, d/b/a Nubrix Security
777 Brickell Ave, Ste 99722, Miami, FL 33131
privacy@posturaiq.com