Last updated: 23 June 2026
apPosture is a self-hosted product. The most important privacy fact is structural: when you run apPosture, your source code, scan data and findings stay inside your own infrastructure. apPosture ("we") does not receive, store or process that data.
All scanning, AI analysis (via a local model) and reporting run on your hardware. We have no access to your code, repositories, scan results or the contents of your environment. Threat-intelligence updates use a local cache; any outbound connection is opt-in and configured by you.
When you submit the contact form on apposture.com we collect the name, work email, company and message you provide, solely to respond to your enquiry. Our web servers keep standard request logs (IP address, user agent, timestamp) for security and reliability. We do not load third-party advertising or cross-site tracking on this site.
To respond to enquiries, provide a demo or proof of concept you requested, and protect the site against abuse. We do not sell personal data.
Contact-form submissions are retained only as long as needed to handle your enquiry and any resulting relationship. Server logs are rotated on a short schedule.
Depending on your jurisdiction, you may have rights to access, correct or delete the personal data we hold about you, or to object to its processing. To exercise them, contact privacy@apposture.com.
This policy covers the apposture.com website and the apPosture product's data model. It is provided in good faith; your use of the product is also governed by your license agreement.
From discovery to a proven attack chain. A PoC in your own environment.