apPosture is built for teams that cannot hand their source code to a vendor cloud. Here is exactly how the platform handles data, how it is hardened, and how to report a vulnerability.
apPosture runs entirely inside your infrastructure via Docker Compose. The vendor never receives your source code, scan data or findings - there is nothing to breach on our side because we do not hold your data.
By default the AI runs on a local model on your hardware - code, prompts and findings are not sent to any third-party AI service. An external model is opt-in, requires explicit consent, and an operator kill-switch can disable it for the whole deployment.
No telemetry and no outbound connection are required. Threat-intel updates use a curated cache and any egress is opt-in, with configurable sources, cadence and proxy.
Because the platform is self-hosted, there is no chain of cloud sub-processors handling your code or results. Your data residency is satisfied by architecture, not by a contract clause.
Role-scoped access (for example PM and Developer roles) with least-privilege defaults and a secure onboarding flow.
The CI agent is checksum-verified - no curl-pipe-shell bootstrap a compromised registry could swap underneath you.
Signature-verified, replay-protected SCM webhooks; an Ed25519-signed license with seat enforcement.
Integration credentials are encrypted at rest; sensitive values (PII, credentials) are masked in evidence and reports.
If the CI gate cannot be evaluated, the build fails and the decision is audited - it never passes silently.
Every action is recorded (actor, action, before, after) with tamper-evident hashing and export.
Scanners use benign markers only - no real outbound exploit, no destructive verbs against live targets.
Findings and exports are protected by an append-only hash chain that an auditor can verify.
apPosture deterministically maps your findings and threats to OWASP Top 10, PCI-DSS v4, ISO 27001, SOC 2, NIST 800-53, HIPAA and GDPR. Because the platform is self-hosted, your compliance posture stays yours: we provide the controls, mapping and verifiable evidence, you retain the data and the attestation.
Need a DPA, SBOM or our compliance pack? Visit the Trust center →
Found a security issue in apPosture? We want to hear from you and will not pursue good-faith research.
Machine-readable policy: /.well-known/security.txt
Other platforms ask you to trust their cloud with your source code. apPosture asks you to trust nothing - it runs entirely inside your infrastructure, with a local LLM, no telemetry and no outbound connection. Your data never leaves, so data-residency and sovereignty requirements are met by design.
From discovery to a proven attack chain. A PoC in your own environment.