Security & trust

A security product has to hold itself to its own standard.

How PosturaIQ handles Microsoft credentials, tenant isolation, least privilege, auditability, and honest reporting of what the platform has and has not done.

No Microsoft passwords, ever

PosturaIQ authenticates to Microsoft through application consent. It never asks for, transmits, or stores a Microsoft user password, and it never requires a standing global administrator session.

Least privilege by default

The default grant is read-only. Write permission is a separate, explicit consent that an organization may decline permanently while still using the platform.

Credentials never reach the browser

Microsoft credentials, tokens, and secrets are held on the backend only. No client-side code path can read them, and platform administration screens never display them.

Strict organizational isolation

Every read and write is scoped to the caller's organization on the server. Organization identifiers supplied by the browser are treated as selection hints and validated against membership before use.

Authorization is server-side

Roles, entitlements, and platform administration privileges are resolved on the backend. The UI hides what a user cannot do; the backend is what actually enforces it.

Everything security-relevant is audited

Permission grants, assessment runs, remediation approvals and executions, entitlement changes, and administrative access are recorded as immutable audit events.

Separation of platform and customer

PosturaIQ platform administration is a distinct authorization domain. Being an administrator inside a customer organization grants no platform privileges, and platform staff access is itself audited.

Honest state reporting

PosturaIQ distinguishes between recommended, approved, executed, and validated. It will report that an operation is unavailable rather than imply an action it did not perform.

Current release

What is operational today.

PosturaIQ states its own maturity plainly, because a security platform that overstates its capabilities is a risk to its customers.

Available

  • Posture, findings, and remediation experience with clearly labeled demonstration data
  • Organization, membership, role, subscription, and entitlement model
  • Microsoft tenant and split assessment/remediation permission model
  • Guided remediation content structure and validation definitions
  • Audit event model for customer and platform activity

Not yet operational

  • Live Microsoft tenant connection and consent flow
  • Assessment execution against a real tenant
  • Assisted and automated remediation execution
  • Automated validation re-query and continuous monitoring
  • Payment processing and self-serve subscription changes

These capabilities are represented in the architecture, permission model, and audit trail so they can be enabled without a redesign — and are labeled in the product until they are real.

Start with a clear posture baseline.

PosturaIQ onboards organizations by invitation. Request access and a member of our team will review your environment and requirements.