Answer the security review with live, signed evidence instead of another PDF.
Your customers, auditors and investors want to see your security posture, and giving them access to your portal is out of the question. Posture Shares gives each of them a read-only view of the figures WASViking measures: the score and what drives it, the trend, the security domains, the remediation in progress and the evidence behind it. You decide how much they see and for how long.
What your reviewer sees after signing in. Fictional data.
Every security review ends with someone outside your company asking for your numbers.
A customer's vendor questionnaire every quarter. The prospect's security team joining the sales call. An investor's data room. An auditor who wants to see the posture, not read about it. The usual answers all fall short: a PDF is out of date the week after it is sent, a spreadsheet is self-declared, and portal access exposes far more than anyone outside should see.
Posture Shares replaces them with one link per relationship. The reviewer sees figures that WASViking measured, never typed by you, in a space that stays current for as long as the relationship needs it and closes the moment you decide.
- Customer vendor questionnaires and security reviews
- Enterprise sales with a security team in the room
- Investor and M&A due diligence
- Auditor evidence, together with the SBOM Evidence Bundle
Four steps, and nothing for you to send by hand.
1. Create the link
Choose the scope (the whole organization or specific domains), the level of detail, the language of the report and how long the link lives. Add the work e-mail of each reviewer, or the Assessor ID their company gave you.
2. WASViking invites each reviewer
Each person gets an e-mail that names your organization. The first time, they create a free reviewer account with a password and a second factor of their own. There is no URL or password for you to forward.
3. The reviewer follows your posture
They open a read-only space with your figures, come back during the life of the link to see what changed since their last visit, and download the signed PDF or the one page assessment statement for their records.
4. You stay in control
You see who opened the space and when. Change the level of detail, extend the link, invite or remove a reviewer, or revoke it entirely, at any time and without issuing a new link.
A space organized around the questions of a vendor assessment.
The reviewer never sees your portal, your raw findings, other targets or your audit log. They see six areas, each answering a part of the assessment they have to complete.
| Area | What it answers |
|---|---|
| Overview | Where the organization stands today, whether it is improving, and what changed since the last visit. |
| Findings & remediation | What is open, fixed or formally accepted, the remediation plan with its dates, and how quickly new findings get a decision. |
| Assessments & evidence | What was assessed and how often, how much of the surface the figures cover, and the control evidence by theme. |
| Reports & history | The signed PDF, the assessment statement, CSV exports and every signed version served. |
| Your access | What the link shows and does not show, its scope and expiry, and how to ask for more detail. |
| Methodology | What was in scope and how every figure is calculated. |
Each link is its own decision about what to disclose.
Level of detail
Minimal shows the score, what drives it and the trend. Standard adds open findings by severity, risk treatment and the remediation plan. Detailed adds remediation performance against SLA. You can raise or lower it later.
Always current or pinned
A live link always shows the latest signed version, for an ongoing relationship. A pinned link keeps the version it was created with, for dated audit evidence.
Scope
Share the whole organization or only the domains of one product. Each domain is its own signed report, and figures are never added up across domains.
Who can open it
Invite people by e-mail or invite a reviewer's company through its Assessor ID. Keep an invitation to one person, or let colleagues at the same company open it, each with their own sign-in.
How long it lives
Set the expiry when you create the link and extend it when the relationship continues. Revoke it at any time; access ends immediately.
A record of every access
The access log shows who opened the space, when, from where and which PDF they downloaded. Every change to the link is kept in its lifecycle audit, so what a reviewer could see on a given day stays answerable.
Measured by the platform, signed when produced, never self-declared.
Measured, not declared
Every figure comes from WASViking's own assessments. Nobody in your organization can type, edit or remove one. The only declared item is the due date of a remediation commitment, and it is labelled as declared.
Evidence origin on every domain
Each security domain says where its evidence came from: externally observed, agent verified, pipeline verified, repository verified or application package analyzed.
Signed and verifiable
Every version of the figures is signed when it is produced. The reviewer can check any PDF or statement they filed against a public verification page. A document altered after download does not match.
Your first share takes a few minutes.
The setup guide walks through creating a link and following who opened it. The assessor guide is the page your reviewer receives: how to open the space and what to file in their assessment.