About & Methodology
What Compliance Posture is
Compliance Posture is a free, independent directory that tracks the security and compliance posture of SaaS tools across 32 frameworks — from SOC 2 and ISO 27001 to HIPAA, GDPR, PCI DSS, and FedRAMP. We are not affiliated with any vendor, auditor, or GRC platform.
How we collect data
We research each tool's public trust center, security page, and compliance documentation. We check vendor pages hosted on platforms like Vanta, SafeBase, Conveyor, and Wolfia. We do not access private audit reports.
How to read our statuses
Yes means the certification or compliance is publicly documented. Partial means it's conditional (e.g., Enterprise plan only, or a signed BAA is required) — we always include a note explaining the condition. No means the vendor documents its certifications publicly and this one is absent. Unknown means we could not verify the status from public sources — it does not mean the vendor lacks the certification.
Data accuracy
Our data reflects publicly available information. If you see an error, submit a correction or claim your profile to verify directly.
Who built this
Compliance Posture is maintained by a small independent team. Data is checked manually; we publish what we can verify and mark the rest as unknown.