F
Trust rating
Fail · 38/100
Procurement snapshot
2 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
Known Breaches
MX Records & Mail Provider
CVE Exposure
Subprocessors & Tech Stack
Estimated remediation effort: 2–5 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change
1 scan · Last scanned February 18, 2026
Your rating
Industry average
Score
100
75
50
25
0
F
38/100
Compliance & Certifications
PCI-DSS
3rd party · QSA
Pro subscribers only
CCPA
Self-reported
Pro subscribers only
GDPR
Self-reported
Pro subscribers only
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Pro subscribers only
Security Posture
4 items need attention
4 passed
0 of 1 fixed
All 1 critical issue marked as fixed
Re-scan to confirm and update your score.
Turn off unknown — it's outdated and unsafe
TLS Configuration
This exposes traffic to interception or tampering using publicly documented weaknesses. positive.co still accepts connections using unknown, an old encryption standard that attackers can exploit to read or tamper with traffic. Every major compliance framework (PCI-DSS, HIPAA, NIST) treats this as a failure. The fix is to simply stop offering it — modern browsers already use TLS 1.2/1.3 automatically, so real visitors won't notice the change.
PCI-DSS 4.0Req 4.2.1
Strong cryptography for transmission
NIST 800-52r2§3.4
TLS 1.0/1.1 must not be used
HIPAA§164.312(e)
Transmission security
How to fix this
1Vercel manages TLS automatically and doesn't expose a minimum-version setting — there's nothing to configure here. If this domain is still showing an outdated TLS version, check whether it's actually fully served through Vercel (e.g. a subdomain or path still pointing elsewhere) rather than assuming it's misconfigured.
ssl_protocols TLSv1.2 TLSv1.3;
2Confirm it worked: search "ssl checker" and enter positive.co — TLS 1.0 and 1.1 should show as not supported.
Report unlocked.
View all 4 passed checks
Known Breaches
MX Records & Mail Provider
CVE Exposure
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Trust Center
trust.positive.co ↗
Security page
positive.co/security ↗
Privacy Policy
positive.co/privacy ↗
DPA (Data Processing Agreement)
positive.co/dpa ↗
Updated recently
Subprocessors List
positive.co/policies/subprocessors ↗
Tech Stack Detected
Subprocessors
Vercel
Similar companies in B2C E-commerce / Retail
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Top AI vendors by trust score
94 companies · LynxRadar ranking
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking