This policy is issued by the operator of PostureRadar, based in the United States. It applies to visitors and customers of postureradar.com. The Service is currently offered to businesses and individuals in the United States.
The short version
We collect the minimum needed to run scans, send you reports, and bill you. We never see your AWS credentials, never get write access to your account, and never read the contents of your data — the objects in your S3 buckets, rows in your databases, and so on. The checks read resource-level configuration and metadata (bucket policies, security group rules, IAM key ages, snapshot sharing permissions, and similar) and, where relevant, GuardDuty's own summarized threat-detection alerts — never your files or database rows themselves. We don't run first-party tracking cookies or ad-tracking analytics on this site.
What we collect
| Data | Why |
|---|---|
| Email address | Account identification, sending scan reports, billing receipts |
| AWS account ID | Displayed in your reports so you know which account a finding is from |
| IAM role ARN(s) + a random external ID | Used to assume the read-only role you deploy in each AWS account you connect, via AWS STS — never a long-lived credential. The external ID is unique per customer and shared across every AWS account you connect under one subscription |
| Scan findings | Resource-level configuration and metadata — e.g. resource names, IAM user names, network rule contents, GuardDuty alert summaries — never the contents of your data |
| Billing information | Handled entirely by Stripe — we never receive or store your card details, only Stripe-assigned customer/subscription identifiers and payment status |
| Activation & "scan again" links | Signed, time-limited, sensitive links we email you to connect an AWS account or trigger an on-demand scan — anyone with the email can use them until they expire (typically 7 days for account-connection links, 30 days for "scan again" links). The "scan again" link includes your customer and AWS account identifiers so it knows what to re-scan |
| Stripe billing portal link | A single-use, time-limited link we email you when you request self-serve subscription management; Stripe can see when you open it |
| Subscription metadata (account quantity, first-scan timestamps, webhook event records, rate-limit records) | Operating your subscription correctly and preventing abuse of self-serve, email-triggered features (e.g. mail-bombing an inbox) |
| Technical/access logs (IP addresses, timestamps, request metadata) | Generated automatically by our infrastructure (AWS CloudWatch, API Gateway) and Cloudflare as part of running the Service and site; used for debugging and abuse prevention |
What we don't do
- We never request or store long-lived AWS credentials. Access to your account is always a temporary, read-only role assumed via STS.
- The IAM role we ask you to deploy has no write, delete, or modify permissions of any kind — see the CloudFormation template itself if you want to verify that yourself.
- We don't read the contents of your S3 objects, database rows, logs, or any other data — only resource configuration and metadata (bucket policies, security group rules, IAM key ages, snapshot sharing permissions, and similar).
- We don't run first-party tracking cookies, ad pixels, or analytics on this site. Our CDN/DNS provider (Cloudflare) may set strictly necessary cookies to serve the site itself.
Who else sees your data
A small number of service providers, and PostureRadar's own team, process data on our behalf, only as needed to run the Service:
- Amazon Web Services — hosts the Service, sends report and notification emails (Amazon SES), and generates operational logs (CloudWatch, API Gateway) that can include IP addresses and request metadata.
- Anthropic — drafts the remediation guidance included in your report, from your scan findings (resource IDs, check names, descriptions, regions — never AWS credentials or the contents of your data).
- Stripe — processes payments for paid subscriptions, and hosts the billing portal we email you a link to when you manage your subscription (Stripe can see that you opened that link).
- Cloudflare — provides DNS and sits in front of our website.
If a scan fails, or an email to you bounces or is flagged as spam, an automated notice is sent to our own support inbox so we can follow up — these notices can include your email address and technical details about the failure, which for a scan failure can include the connected role's ARN and External ID. They never include your scan findings or the contents of your AWS account.
We don't sell your data to anyone, ever.
How long we keep it
- Account records (email address, connected AWS account role ARN(s) and external ID, subscription status, Stripe customer/subscription identifiers): kept while your subscription is active, and after cancellation for as long as needed in case you resubscribe or for billing or legal purposes. We don't currently auto-delete these on a fixed schedule after cancellation — see "Deletion on request" below for how to have your account record removed sooner.
- Scan findings / reports: we don't maintain a searchable archive or dashboard of past findings. Each report is generated fresh and emailed to you. Operational copies may exist temporarily in Amazon SES's delivery records.
- Signed links (account connection and "scan again" links): expire automatically — 7 days for connection links, 30 days for "scan again" links.
- Technical / access logs (CloudWatch, API Gateway, Cloudflare): retained for a limited period, generally 30–90 days, as part of normal operations and security monitoring. Our own AWS account's CloudTrail (a record of API activity within our infrastructure, not your AWS account) is retained longer, up to 365 days, for security auditing.
Deletion on request isn't yet an automated, instant process — it's handled manually by our team once we've verified the request, and we'll complete it within a reasonable time, subject to any legal retention obligations.
Your privacy rights
Depending on where you live, you may have rights regarding your personal information, including the right to know what we collect, use, and disclose about you; request access to or a copy of it; request correction of inaccurate information; request deletion of it; and opt out of the "sale" or "sharing" of personal information — we don't sell or share personal information for cross-context behavioral advertising.
California residents (CCPA/CPRA): you have the rights listed above. We don't sell or share your personal information as those terms are defined under California law. To exercise any of these rights, email us at the address below; we'll verify your request and respond within the time required by law. You won't be discriminated against for exercising your rights.
Other U.S. states: if your state has enacted a comprehensive privacy law that grants you similar rights, you can contact us to exercise them the same way.
To make a request, email us at the contact address at the bottom of this policy. We may need to verify your identity before fulfilling it.
Your choices
- You can cancel your subscription at any time.
- You can remove the deployed IAM role from your AWS account at any time, which immediately prevents any future scan of that account.
- You can request deletion of your account record by emailing us.
Children's privacy
The Service is intended for businesses and individuals managing their own AWS infrastructure, not for children. We don't knowingly collect data from anyone under 16.
Changes to this policy
If we make material changes to this policy, we'll notify active subscribers by email before the changes take effect.
Contact
Questions about this policy, or requests to access or delete your data: [email protected].
