About & Methodology

What Compliance Posture is

Compliance Posture is a free, independent directory that tracks the security and compliance posture of SaaS tools across 32 frameworks — from SOC 2 and ISO 27001 to HIPAA, GDPR, PCI DSS, and FedRAMP. We are not affiliated with any vendor, auditor, or GRC platform.

How we collect data

We research each tool's public trust center, security page, and compliance documentation. We check vendor pages hosted on platforms like Vanta, SafeBase, Conveyor, and Wolfia. We do not access private audit reports.

How to read our statuses

Yes means the certification or compliance is publicly documented. Partial means it's conditional (e.g., Enterprise plan only, or a signed BAA is required) — we always include a note explaining the condition. No means the vendor documents its certifications publicly and this one is absent. Unknown means we could not verify the status from public sources — it does not mean the vendor lacks the certification.

Data accuracy

Our data reflects publicly available information. If you see an error, submit a correction or claim your profile to verify directly.

Who built this

Compliance Posture is maintained by a small independent team. Data is checked manually; we publish what we can verify and mark the rest as unknown.

Data sourced from public trust centers. Not legal or compliance advice.

Logos and trademarks are property of their respective owners. Use does not imply endorsement, affiliation, or sponsorship.

© Compliance Posture 2026