WASViking Docs
⌘K
Compliance

Assessor guide to a Posture Share

A vendor sent you a Posture Share. What it is, what you can see and do with it, how to verify it, and how to use it in a third-party risk assessment.

This guide is for the person on the receiving end: a third-party risk analyst, a customer security team, an auditor. A vendor you assess uses WASViking® and you got an e-mail with the address of the assessor portal and a temporary password. Everything below is about what you can do with them. If you are the one sharing, start with Posture Shares.

What you received

A Posture Share is a read-only space, at posture.wasviking.com, with the vendor's security posture as measured by the WASViking platform: score, trend, findings by severity and treatment, the assessments that ran, control evidence by theme, remediation deadlines and signed reports. It is built to be followed during the whole relationship, not read once.

It is not a certification, an audit opinion or a statement of compliance, and it is not a window into the vendor's console. It is evidence you can verify, attach to your assessment and come back to.

Before you start

Question Answer
Do I need an account? Yes, a free one, and it takes a minute: the first sign in with the temporary password creates it. One account serves every vendor that invites your e-mail.
Do I install or configure anything? Only an authenticator app on your phone, for the second factor. The portal itself is a web page.
Is there a cost for me? No.
Do I sign anything with WASViking? No. The share is a disclosure from the vendor to you, under the confidentiality terms the two of you already have.
Does opening it touch the vendor's environment, or mine? No. You read figures that were already measured and signed. Nothing is scanned when you open the page.
Which language is it in? The one you choose. English and Brazilian Portuguese are available, for the portal, the vendor spaces, the PDFs, the CSV files and the e-mails of your account. It starts as the language the vendor picked for your link; change it in the language menu at the top of the portal or on the Account page. With an older link and password and no account, it stays the one the vendor picked.

Open the share

  1. WASViking e-mails you, on behalf of the vendor, the address of the assessor portal, https://posture.wasviking.com/, and a temporary password. It is always that address: type it yourself if you ever doubt a message.
  2. Sign in with your e-mail and the temporary password. It shows nothing of the vendor: it only proves that you read that mailbox.
  3. Create your account: your name, your company, a password of your own, and two factor authentication with an authenticator app (mandatory, with ten backup codes to keep). Accept the terms, and My vendors opens with the vendor that invited you. One click opens its shared space.
  4. From then on you sign in with your e-mail, your password and the code of the app. The temporary password is erased.
  5. The temporary password is valid for 7 days. If it expired, or you lost the e-mail before ever signing in, ask the vendor to use Resend. Once you have an account, a forgotten password is yours to recover, with Forgot the password? on the sign in page. A vendor never touches it.
  6. Type carefully. Repeated wrong temporary passwords lock that invitation for a while, and continued attempts end it until the vendor sends a new one. Nobody else is affected.
  7. If colleagues need access, do not forward your message: every person signs in with an account of their own. Colleagues who belong to your organization in the portal open what invited you, as described in Assessor account; anyone else asks the vendor for an invitation.

The vendor sees when its shared space was opened for the first time, and its access log names the person behind every visit.

The only password WASViking ever e-mails you is that temporary one, and the message names the vendor. If you created an assessor account, it also sends the notifications you can switch off, described in Assessor account. A message you did not expect deserves a call to your contact at the vendor before you open anything.

The six areas

Area Use it to answer
Overview Where does this vendor stand today, is it getting better or worse, and what changed since my last visit?
Findings & remediation What is open, what was fixed, what was formally accepted, how old is the oldest open item, and is there a deadline for it?
Assessments & evidence What was assessed, how often, how much of the surface the figures stand for, and which control requirements the evidence relates to.
Reports & history What can I download and file, and which signed versions have I been served?
Your access What this link shows, what it does not show at its level, what is never shared, the scope, the expiry, the form to ask for more, and the form to ask for an assessor account invitation.
Methodology What was in scope and how every figure is calculated.

All areas load with the page. Moving between them is not another view of the link and does not use up a view cap the vendor may have set. When a link covers several domains, a selector at the top switches between them. Each domain is its own report, with its own score, signed version and trend. Figures are never added up across domains.

From your assessment checklist to the screen

What your assessment asks Where it is answered
What level of access do we get to the results? Your access: the disclosure level, the included and not included items, the scope and the expiry.
Is there a portal or a dashboard, or only a report? The shared space itself, plus the PDF when you need a document.
How do we follow vulnerabilities over time? Findings & remediation: open findings by severity, issue categories with the age of the oldest open one, 30 day activity and the month by month treatment history. Overview: the 90 day and 12 month trend.
Is there a remediation plan with dates? Remediation plan, at the top of Findings & remediation: the target, the declared due date and the progress measured against the findings that were open when the deadline was declared. When open findings have no deadline, Ask for a remediation deadline sits right below it.
Where is the evidence for compliance controls? Control evidence by theme in Assessments & evidence: nine themes, each next to the requirement it relates to in PCI DSS, ISO 27001, SOC 2, NIST CSF 2.0, CIS Controls v8, the Brazilian central bank rules (CMN 4.893 and BCB 85), LGPD and GDPR, plus the treatment picture per framework.
Which assessments were executed, and how often? Assessments executed: one row per assessment type with the last execution, the cadence, the executions in the last 90 days and a 12 month strip.
Can we export the results? Reports & history: the signed PDF, the consolidated PDF, the one page assessment statement and three CSV files (current metrics, score and treatment history, signed versions).
Can we follow each finding, one by one? Findings register, in Findings & remediation, when the vendor turned it on for your link: type, severity, status, dates, age, SLA state and declared deadline per finding. If it is not there, ask for it in Your access.
Does the vendor react to what is found? Responsiveness, in Findings & remediation: the share of open findings that carry a decision, the ones waiting more than 30 days, and the median time to the first response.
Are there metrics and a history of treatment? Remediation performance against SLA at the Detailed level, the treatment history at Standard and above, and the signed versions ledger.
How do we know the numbers are real? Evidence rules, the evidence origin on every figure, and the verification link of each signed version. See below.

How much you see

The vendor chooses a disclosure level per link and can change it later without issuing a new URL:

Level What it shows
Minimal Score and what drives it, trend over 90 days and 12 months, framework correlation indicators, assessments executed, and the control themes with their references, without counts.
Standard Adds open findings by severity, issue categories, 30 day activity, risk treatment (open, accepted, remediated), responsiveness, the treatment history and the remediation plan.
Detailed Adds remediation performance: median time to remediate and SLA percentages.

Four optional sections sit on top of the level: Security domains, Infrastructure, Active security controls and the Findings register, which is never on by default. A block with no data behind it is absent, never shown empty, and a domain that was never assessed reads "Not assessed", never clean.

If your assessment needs more, open Your access and use Ask for more detail. You tick what you need from a fixed list, the vendor gets an email, and the decision stays with them. There is no free text, and one request a day is accepted. When they raise the level, you only reload the page.

Why you can rely on the figures

  • Measured, not declared. Every figure comes from the platform's own assessments. The vendor cannot type, edit or remove one. The single declared item is the due date of a remediation commitment, and it is always labelled as declared.
  • Evidence origin. Domain figures say where the evidence came from: externally observed, agent verified, pipeline verified, repository verified or application package analyzed.
  • Fixed means fixed. A finding counts as remediated when it is closed as fixed or is no longer observed by the source that reported it. If a later assessment detects it again, it reopens and counts as open.
  • Accepted is not fixed. An accepted risk leaves the score but stays listed as accepted, apart from remediation, with the share of acceptances that have a recorded reason and a review date still ahead.
  • A false positive never counts as remediated.
  • Continuous has to prove it. A continuous source with no evidence in the last 30 days reads "No recent execution".

Verify a signed version

Every version of the figures is signed when it is produced.

  1. Open Reports & history and find Signed versions.
  2. Click Verify on a version. It opens posture.wasviking.com/verify/<code>/, a public page that needs no password and shows only the organization, the score, the signing time, the key version, the signature and the content hash.
  3. Compare the hash with the one printed in the authenticity block of the PDF or of the assessment statement you filed. Same hash, same content.
  4. For an automated check, the same page offers the record as JSON.

A PDF that was altered after download will not match. A version that was never signed by WASViking has no verification page.

Following a vendor over time

  • Come back whenever you need. What changed since your last visit opens the Overview with the differences, including new remediation commitments and commitments that changed status.
  • The chip at the top says Always current (the link follows every new signed version) or Fixed version (the link is pinned to one version, the usual choice for time-stamped audit evidence).
  • A remediation commitment reads In progress, Overdue, Delivered, Closed with accepted risk, No longer applicable or Withdrawn, and says when the delivery happened after the due date. It is never edited: a vendor that needs a new date withdraws it and declares another, and the withdrawn one stays visible for 90 days. Findings that appear after the declaration never enter the commitment, so the goalposts do not move in either direction.
  • No deadline for what worries you? At the Standard level or above, use Ask for a remediation deadline: tick the severities, the vendor gets an email and decides. There is no free text, and one request a day is accepted. A deadline they declare shows in the plan and in the notice of your next visit, and from then on the delivery is measured.
  • Access expires in shows how long the link lives. A link never expires more than 180 days ahead, so in a long contract ask the vendor to renew it along the way. URL and password stay the same.

What to file in your assessment

Document When to use it
Assessment statement (PDF, one page) The attachment for a vendor assessment record: what was assessed, when, by which platform, the score at signing and the full verification link. It only exists once at least one assessment ran in the scope.
Posture report (PDF) The full report of the domain on screen, tied to one signed version.
Consolidated report (PDF) Links with several domains: every domain report behind a summary cover, each with its own signature. Nothing is added up.
CSV: current metrics One figure per row with a stable key, ready for your own risk register or GRC tool.
CSV: score and treatment history Weekly over 90 days and monthly over 12 months.
CSV: signed versions The ledger, with the full verification link of each version.
CSV: findings register Only when the register is shared with you: one row per finding, ready to import into your own tracking.

A file never carries a figure the page does not show at your disclosure level.

What you never see, and why

  • Hosts, URLs, payloads, packages or CVE identifiers.
  • Any single finding, unless the vendor shares the findings register with you, and then only its type, severity, status and dates.
  • The size of the vendor's fleet or the list of their targets.
  • Raw evidence, proof of concept, or anything outside the shared scope.

That boundary is what lets a vendor keep a share open continuously instead of sending a redacted PDF once a year. If your process requires the technical detail of a finding, that is a conversation with the vendor, outside the Posture Share.

Assessor account

Every recipient has one: it is how you get in. It is free, and if you follow more than one vendor it gives you one place for all of them.

  • How you get one. From a vendor's invitation: the vendor invites your e-mail and WASViking sends you the temporary password of the first sign in. Already have an account? A new vendor only has to invite the same e-mail: you get a notice with no password in it, and the vendor shows up on your page.
  • How to ask for one. On a link from before the portal, where you came in with a shared link and password and no invitation? Open Your access and use Ask for an assessor account invitation: enter the e-mail you want the account on. The vendor is notified and decides; nobody is invited until it agrees, and the invitation never carries the password of the link. The address you enter is sent to the vendor and kept in the access log of that link. One request a day per link.
  • What you get. My vendors: one row per vendor with the score, the 90 day trend, the open critical and high findings, the declared deadlines running or overdue, the last signed version and how long your access lasts. Figures follow what each vendor discloses; a Minimal link shows no counts there either. One click opens that vendor's shared space, with no link password to keep. Above the list, four figures sum up the portfolio: how many vendors you follow, their average score, how many have an overdue deadline and how many accesses end within 14 days. Search by vendor name or domain, and order by name, lowest score, most open criticals or access ending first; a figure a vendor does not disclose always sorts last.
  • Your organization. You assess vendors for a company, and a vendor may not know which of its people to invite. So the portal works by organization: the first account with a corporate e-mail domain creates the organization of that company and owns it; a colleague with an address of the same domain is offered Ask to join, and the owner or an admin decides. Nobody joins by the domain alone. An invitation that reaches a member belongs to the organization, so every member opens that vendor, each with their own password and authenticator app, and My vendors says Invited as when the vendor typed a colleague's address. When you join, the vendors that invited your address pass to the organization; when you leave or are removed, you stop opening its vendors at once and the organization keeps them, including the ones that invited your address. A vendor may restrict an invitation to Only this person: then colleagues do not open it. The Organization page shows the people, their roles (the owner manages roles and the name; admins approve requests and remove members), the requests to join, the e-mail domains and the latest activity. A declared domain only lets colleagues ask to join and routes nothing. An address at a public mailbox provider (a free webmail) never forms an organization and stays personal.
  • Prove your domain. The owner can prove that the organization controls an e-mail domain: Get the DNS record (it asks for your password and a fresh code) shows a TXT record to publish at _wasviking-assessor.<domain> (your domain), and Check now asks the DNS. The value is unique to your organization and that domain, so nobody else can use your record, and one domain is proven by one organization only. Keep the record published: it is asked again every day, and the proof ends when it is gone three days in a row (a DNS outage never counts). Once a domain is proven, an invitation any vendor sends to an address of that exact domain lands in your organization from the start, whoever was typed (a colleague, a shared mailbox such as a team address, somebody who left); the owner and the admins get an e-mail, every member opens that vendor, and the typed person opens it once a member. The vendor is shown your proven domain and the name of your organization before it sends. Up to five domains per organization; a sub domain is a different domain.
  • Assessor ID. An organization with a proven domain has one, in the form AO-XXXX-XXXX-XXXX-XXXX. Put it in your vendor onboarding instructions: the vendor types it instead of an e-mail, there is no address to get wrong, and the invitation goes to the organization itself. It opens nothing by itself. The owner can replace it at any time; the old one stops working at once and the vendors you already follow are not affected.
  • Ask a vendor. You do not have to wait for an invitation. On Vendor requests, the owner or an admin of an organization with a proven domain types the corporate domain of a vendor (or the request code the vendor published, in the form VR-XXXX-XXXX-XXXX-XXXX), picks a purpose (vendor due diligence, contract renewal, regulatory requirement, incident follow-up) and, if you want, a short reference of your own (letters, digits and dashes). There is no free text. If that company uses WASViking, proved that domain and takes requests, the people who manage its Posture Share read the domain your organization proved, the name it gave itself, your name and e-mail, the purpose and the reference, and decide. WASViking never tells you whether a company is a customer: every request gets the same answer, and it reads Waiting until it expires after 30 days unless the vendor approves, in which case it turns Approved and the vendor shows up under My vendors. No answer looks the same whatever the reason. A request shares nothing by itself: the vendor that approves chooses what it discloses. Up to 20 requests a day for your organization, one per domain every 30 days; every member follows what was asked.
  • Finding your way. The menu on the left has My vendors and Vendor requests, then Settings (Profile, Organization, Security, Notifications) and Resources (this guide, Terms and privacy), with the sign out at the foot. Profile holds your name, your company, the language and the time zone, and is where the account is deleted. The time zone words the dates and times of your account (last sign-in, acceptance of the terms); signed evidence from a vendor, such as signature times, watermarks, PDFs and CSV files, always states UTC, so everyone reads the same instant; your e-mail identifies the account and does not change. The top bar has the language menu and your name, e-mail and company. An open vendor stays inside the same portal: its areas (overview, findings and remediation, assessments and evidence, reports and history, your access, methodology) show under My vendors in that menu, and on a phone as a tab bar at the top of the page.
  • What you are told. Every member of an organization is told about the vendors the organization follows, each under their own choices on the Notifications page. One e-mail a day at most, and only when something changed at a vendor you follow: a remediation deadline declared, missed, delivered, closed with accepted risk or withdrawn; a score move of 3 points or more since the last figure you were told; your access expiring in 14 days and in 3 days, or ended. The message says only what that vendor's link already shows you: a Minimal link reports the score and nothing about deadlines, and no message ever carries findings, addresses or passwords. Nothing is sent about a vendor on the day you start following it. Choose the subjects on the Notifications page, or use the link at the foot of any message to stop all of them without signing in.
  • How it is protected. A password under the same strength rule as the links, two factor authentication with an authenticator app from the very first sign in, ten single use backup codes, a lock after repeated wrong attempts, and an invisible reCAPTCHA check on every credential form.
  • Sessions. A session ends on its own after 8 hours. On the Security page, Sign out of all other sessions ends every session but the one you are using, for when you used a shared or lost device.
  • New phone. On the Security page, Authenticator app moves the second factor to another phone or app: type your password and a current code (or a backup code, when the old phone is gone), scan the new QR code and confirm with a code from the new app. Until that confirmation nothing changes, and a set up you abandon expires in 15 minutes. Once confirmed, the previous app stops working, every other session of the account ends and new backup codes are issued.
  • What you accept. The Assessor Portal Terms of Use and the Assessor Portal Privacy Notice, both published in the WASViking Trust Center so your legal team can read them before you sign in. The portal asks you to agree to each one at the first sign in and again whenever a version changes; declining signs you out and is recorded. Terms and privacy keeps the record of what you accepted: the version, the date and a fingerprint of the exact text. How shared data is handled, including what is never shared, is on the Posture Share and Assessor Portal Data Handling page.
  • Who stays in control. The vendor. It can remove an invitation at any time, which ends it for everyone who could open it, or restrict it to the invited person, and it sees your e-mail next to every visit and download in its own access log. Once its shared space was opened, it also sees the name of your organization and how many people it has, never the list of members. A vendor never sees which other vendors you or your organization follow.
  • Leaving. Delete the account yourself on the Profile page. A vendor that invites your e-mail again starts a new one.

Good to know

  • Your visits are recorded. Each visit and each download is logged for the vendor with the time and the IP address, and downloads with the hash of the file. You do not see that log.
  • Read the scope first. The figures stand for the scope the vendor shared. Shared scope and Assessment coverage tell you how much of the surface that is, and where the gaps are.
  • One person, one access. Your account is yours alone. If several people on your side need access, ask the vendor to invite each e-mail: every person gets a named access of their own, and the vendor's log says who opened what.
  • There is no API for recipients today. The CSV files are the way into your own tools.

Common questions

I lost the e-mail, or I forgot my password. Never signed in yet? Ask the vendor to use Resend on your address: you get a new temporary password and the old one stops working. Already have an account? Use Forgot the password? on the sign in page. Lost the phone with the authenticator app? Use one of your backup codes.

The link expired. Ask the vendor to renew it. Your account stays the same, and the vendor shows again under My vendors.

The score did not move but the version number did. A new version is signed whenever any figure changes, even when the score is the same.

The vendor accepted a critical risk. Did the score improve? Yes, and the report says so: accepted findings leave the score and stay listed under risk treatment, never as remediated.

Can I get the list of vulnerabilities? You can get the findings one by one, if the vendor agrees: ask for the findings register in Your access. It lists each finding by type, severity, status and dates. What locates or reproduces a finding (asset, address, URL, CVE identifier, evidence) is never shared through a Posture Share.

Assessing other vendors?

Ask them for a Posture Share. Any WASViking customer can issue one in a few minutes, following Posture Shares, and you follow each third party on measured, signed evidence instead of a questionnaire. The full visibility contract, from the vendor's side, is in Posture Shares.