Frequently Asked Questions
For CISOs & IAM Directors
No. ISPM tools (like Silverfort, Zscaler, or Authomize) continuously monitor your live identity environment for threats and misconfigurations. IAM Posture™ is a vendor selection intelligence product — we help you evaluate and choose the right IAM platform before you deploy it. We don't connect to your directory, we don't monitor your sessions, and we don't replace your security tooling. We replace the 6–12 week consulting engagement you'd otherwise commission to build a vendor shortlist.
Gartner and Forrester score vendors on broad market dimensions for the average enterprise buyer. IAM Posture™ scores vendors against your specific requirements — your stack, your compliance mandates, your org maturity, your use cases. A vendor in the Leaders quadrant may be ranked #4 for your specific deployment. We produce a personalized IAM Verdict, not a generic market map.
Yes. Enterprise subscribers can request custom pillar weighting — shifting emphasis between Feature Fit, Governance, Cost Alignment, and the other 4 pillars to match your organization's priorities. Every score is traceable to its source, so you can audit and challenge any dimension. If you find a logic flaw in how your requirements were matched, our guarantee covers a free manual rebuild.
Yes. Org size and maturity fit are explicit scoring pillars. A 300-person company evaluating Okta vs. Microsoft Entra gets different recommendations than a 50,000-person enterprise doing the same comparison. Vendor complexity, implementation overhead, and licensing model are all weighted against your actual scale and team capacity.
Vendor Neutrality & Trust
Structurally: we charge buyers, never vendors. No vendor can purchase a higher score, a featured placement, or preferential access to our scoring methodology. Revenue comes exclusively from buyer subscriptions and one-time report purchases. The full methodology is published at iamposture.com/methodology — every score maps to a cited source (Gartner MQ position, Forrester Wave, G2 verified reviews, NIST documentation, or hands-on lab testing). You can open any score and trace it back to its origin.
No. Your assessment responses are never shared with vendors unless you explicitly use the "Contact Vendor" feature. We don't run drip campaigns on your behalf. No gated demo, no mandatory sales call. Your data is used to compute your results and, in aggregate-anonymized form, to improve our benchmarks.
Data & Coverage
Core scoring data is refreshed quarterly. Major product releases, M&A events, pricing changes, and significant security incidents are typically reflected within 48 hours of public announcement. Enterprise subscribers receive priority data updates and are notified when a shortlisted vendor has a material change.
We cover IGA (Identity Governance & Administration), PAM (Privileged Access Management), CIEM (Cloud Infrastructure Entitlement Management), workforce and customer IAM, NHI and secrets management, and hybrid identity bridges. We do not score ISPM monitoring tools — those are a separate product category entirely (see the ISPM question above).
Getting Started
IAM Posture™ is a vendor-neutral IAM selection intelligence platform. We score 52+ IAM products across 180+ governance dimensions, then rank them against your specific requirements — your stack, your compliance mandates, your org size — to produce a defensible shortlist you can take to your board. We are not a monitoring tool, an advisory firm, or a lead-gen site. We are a structured evaluation engine.
The core directory, basic LENS assessment results, and TCO calculator are free. The full IAM Verdict report — which includes the scored shortlist, gap intelligence brief, and 5-year TCO projection — is a one-time $499 purchase. It never expires.
All sales are final due to the digital nature of our research. However, if you can demonstrate that our matching engine failed to factor in one of your explicitly stated requirements, we will audit the logic and rebuild your report manually at no charge within 48 hours.
Scoring & Methodology
We use the LENS™ framework, which evaluates vendors across 9+ pillars: Identity Foundation, Identity Governance, PAM, CIAM, Threat Posture, NHI & Secrets, Agentic Readiness, Zero Trust, Platform Fit, and Commercial Fit. Each pillar is composed of multiple dimensions (180+ total) weighted by your stated priorities. Sources include product documentation audits, hands-on technical testing, verified compliance registries, and cross-validation against Gartner, Forrester, and G2 data.
LENS is our guided evaluation tool that captures your requirements — use cases, budget, compliance mandates, tech stack, org size, and maturity level — then scores all 52+ vendors in our database against those inputs and returns a ranked shortlist with explained scores.
Data & Privacy
Your responses are used strictly to compute and store your results. We anonymize and aggregate data for industry benchmarking (e.g., "CISOs in healthcare weight NHI Readiness 2.3x higher than average"). We never share your raw assessment responses with vendors unless you explicitly use the Contact Vendor feature.
We use Supabase for secure data storage with encryption at rest and in transit. You can export or delete your data at any time through the Settings panel.
Still have questions?
Contact our Support Team