Security

The strongest data-residency story is sending nothing at all

apPosture is built for teams that cannot hand their source code to a vendor cloud. Here is exactly how the platform handles data, how it is hardened, and how to report a vulnerability.

Our security model

Sovereignty by architecture

Self-hosted by design

apPosture runs entirely inside your infrastructure via Docker Compose. The vendor never receives your source code, scan data or findings - there is nothing to breach on our side because we do not hold your data.

Local LLM by default

By default the AI runs on a local model on your hardware - code, prompts and findings are not sent to any third-party AI service. An external model is opt-in, requires explicit consent, and an operator kill-switch can disable it for the whole deployment.

No phone-home

No telemetry and no outbound connection are required. Threat-intel updates use a curated cache and any egress is opt-in, with configurable sources, cadence and proxy.

No sub-processors for your data

Because the platform is self-hosted, there is no chain of cloud sub-processors handling your code or results. Your data residency is satisfied by architecture, not by a contract clause.

Platform hardening

How the platform itself is secured

Scoped RBAC

Role-scoped access (for example PM and Developer roles) with least-privilege defaults and a secure onboarding flow.

Checksum-pinned agent

The CI agent is checksum-verified - no curl-pipe-shell bootstrap a compromised registry could swap underneath you.

Signed, verified integrations

Signature-verified, replay-protected SCM webhooks; an Ed25519-signed license with seat enforcement.

Encrypted secrets & masking

Integration credentials are encrypted at rest; sensitive values (PII, credentials) are masked in evidence and reports.

Fail-closed gate

If the CI gate cannot be evaluated, the build fails and the decision is audited - it never passes silently.

Append-only audit log

Every action is recorded (actor, action, before, after) with tamper-evident hashing and export.

Safe-by-design probing

Scanners use benign markers only - no real outbound exploit, no destructive verbs against live targets.

Tamper-evident evidence

Findings and exports are protected by an append-only hash chain that an auditor can verify.

Compliance

Your posture, mapped - not our certificate

apPosture deterministically maps your findings and threats to OWASP Top 10, PCI-DSS v4, ISO 27001, SOC 2, NIST 800-53, HIPAA and GDPR. Because the platform is self-hosted, your compliance posture stays yours: we provide the controls, mapping and verifiable evidence, you retain the data and the attestation.

Need a DPA, SBOM or our compliance pack? Visit the Trust center →

Vulnerability disclosure

Found a security issue in apPosture? We want to hear from you and will not pursue good-faith research.

  • Email security@apposture.com
  • Include steps to reproduce and impact
  • Please do not test against other customers or run destructive payloads
  • Give us reasonable time to remediate before public disclosure

Machine-readable policy: /.well-known/security.txt

Trust & data residency

Sovereignty is the default, not an add-on

Other platforms ask you to trust their cloud with your source code. apPosture asks you to trust nothing - it runs entirely inside your infrastructure, with a local LLM, no telemetry and no outbound connection. Your data never leaves, so data-residency and sovereignty requirements are met by design.

Self-hosted Air-gapped Local LLM No phone-home Safe-by-design probes Sensitive data masked 7 frameworks mapped

See how it runs entirely in your environment

From discovery to a proven attack chain. A PoC in your own environment.