Skip to content
Marketing block

Security Posture Band

The compliance and security facts a procurement reviewer asks for, stated as figures with their scope rather than as badges.

116 linesNo dependenciesAdded 9 Sept 2026
  • stats
  • security
  • compliance
  • trust
  • enterprise

What's included

  • components/security-posture-band.tsx
  • No runtime dependencies

Works with

  • React
  • Next.js
  • Tailwind CSS
  • TypeScript

npx hoverlab add security-posture-band

Or over MCP, from your editor's agent — no account needed.

License

Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.

Was this useful?

Start a page with this section — add more, order them, and leave with the page source.

Preview

Security

What a reviewer will ask, answered first

A wall of certification logos answers none of these. Each figure names its scope, because a control that covers one environment and not the other is the thing a reviewer is looking for.

Encryption at rest
AES-256

Every store, including backups and the search index.

Median patch time
31 h

Critical CVEs, from advisory to production, trailing year.

Data regions
4

EU, US, UK and AU. Pinned per workspace, never replicated out.

Access reviews
Quarterly

All production access, logged and exportable.

Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.

Source

components/security-posture-band.tsx
/**
 * <SecurityPostureBand> — The compliance and security facts a procurement reviewer asks for, stated as figures with their scope rather than as badges.
 *
 * Same shape as the benchmark band and a different job, which is worth
 * saying because the temptation is to make one component do both. This one
 * answers a procurement review, and the wrong answer it exists to replace
 * is a row of certification logos — those say an audit happened, not what
 * it covered, and "what does it cover" is the entire question a reviewer
 * has.
 *
 * So every tile's detail names a scope rather than a standard. "AES-256"
 * is not the answer; "AES-256, every store, including backups and the
 * search index" is, because the gap a reviewer is looking for is the store
 * somebody forgot. A tile whose detail cannot name a scope should be cut
 * rather than padded.
 *
 * Accessibility is the <dl> pairing, for the same reason as the benchmark
 * band: heard rather than seen, "Data regions, 4" is a fact and a bare "4"
 * is noise. Worth restating here because this block is the more likely of
 * the two to be edited down to bare figures by someone in a hurry, and the
 * <dt>/<dd> structure is what must survive that edit.
 *
 * The demo defaults to four filled tiles. Two would fit the grid and read
 * as an unfinished section; six wraps to a second row where the eye stops
 * treating them as one band.
 *
 * Server component — no state, no interactivity, nothing that needs a
 * browser.
 */

export interface SecurityPostureBandMetric {
  label: string
  value: string
  /** One clause on what moved, or omit for a bare figure. */
  detail?: string
}

export interface SecurityPostureBandProps {
  eyebrow?: string
  heading?: string
  intro?: string
  metrics?: SecurityPostureBandMetric[]
  className?: string
}

const METRICS: SecurityPostureBandMetric[] = [
  { label: "Encryption at rest", value: "AES-256", detail: "Every store, including backups and the search index." },
  { label: "Median patch time", value: "31 h", detail: "Critical CVEs, from advisory to production, trailing year." },
  { label: "Data regions", value: "4", detail: "EU, US, UK and AU. Pinned per workspace, never replicated out." },
  { label: "Access reviews", value: "Quarterly", detail: "All production access, logged and exportable." },
]

/*
  Per-instance id, hashed from the heading.

  The literal id this replaced collided the moment a second page used this
  block: `aria-labelledby` pointing at a duplicated id resolves to whichever
  element is first in the document, so the second copy of the section was
  announced with the first copy's heading. Server component, so there is no
  `useId` available -- hashing the heading gives each instance its own target
  without a hook, a prop or a counter, and stays stable across server and
  client renders in a way a counter would not.
*/
function instanceId(...parts: (string | undefined)[]): string {
  const text = parts.filter(Boolean).join('|')
  let hash = 0
  for (let i = 0; i < text.length; i++) hash = (Math.imul(hash, 31) + text.charCodeAt(i)) | 0
  return (hash >>> 0).toString(36).slice(0, 6)
}

export function SecurityPostureBand({
  eyebrow = "Security",
  heading = "What a reviewer will ask, answered first",
  intro = "A wall of certification logos answers none of these. Each figure names its scope, because a control that covers one environment and not the other is the thing a reviewer is looking for.",
  metrics = METRICS,
  className,
}: SecurityPostureBandProps) {
  const headingId = `security-posture-band-heading-${instanceId(heading, eyebrow)}`
  return (
    <section
      aria-labelledby={headingId}
      className={`w-full bg-background px-6 py-16 sm:py-20 ${className ?? ''}`}
    >
      <div className="mx-auto max-w-5xl">
        <p className="text-sm font-medium text-primary">{eyebrow}</p>
        <h2
          id={headingId}
          className="mt-2 text-3xl font-semibold tracking-tight text-foreground sm:text-4xl"
        >
          {heading}
        </h2>
        <p className="mt-3 max-w-2xl text-base text-muted-foreground">{intro}</p>

        {/*
          A <dl>, not a grid of divs. Each tile is a term and its value, and
          a screen reader reading "Uptime, 99.98%" is the whole point of the
          section — a div soup reads as five unrelated numbers.
        */}
        <dl className="mt-10 grid grid-cols-1 gap-px overflow-hidden rounded-xl border border-border bg-border sm:grid-cols-2 lg:grid-cols-4">
          {metrics.map((metric) => (
            <div key={metric.label} className="min-w-0 bg-card p-6">
              <dt className="break-words text-sm font-medium text-muted-foreground">{metric.label}</dt>
              <dd className="mt-2 break-words text-3xl font-semibold tabular-nums tracking-tight text-foreground">
                {metric.value}
              </dd>
              {metric.detail ? (
                <p className="mt-1 text-sm text-muted-foreground">{metric.detail}</p>
              ) : null}
            </div>
          ))}
        </dl>
      </div>
    </section>
  )
}

Before you paste

  • Styling is Tailwind utility classes on semantic tokens (bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.
  • Nothing to install. No component library, no icon package.
  • Every prop has a default, so it renders standalone before you wire it up.

Where it goes

Drop it at components/security-posture-band.tsx and import it where you need the section:

import { SecurityPostureBand } from '@/components/security-posture-band'

Customize

2 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.

Props

Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.

PropTypeDefault
eyebrowstring"Security"
headingstring"What a reviewer will ask, answered first"
introstring—
metricsSecurityPostureBandMetric[]METRICS
classNamestring—

Not using React?

The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.

security-posture-band.html
<!--
  Security Posture Band — markup from the Hoverlab catalog.

  This is the block rendered once to HTML and wrapped as a component
  file. It is not a port of the React source: the Tailwind classes carry
  the design, which is the part that took the work, and they are the same
  in every framework.

  This block has no interactive behaviour, so nothing is missing.
-->
<section aria-labelledby="security-posture-band-heading-1082x0" class="w-full bg-background px-6 py-16 sm:py-20 ">
  <div class="mx-auto max-w-5xl">
    <p class="text-sm font-medium text-primary">Security</p>
    <h2 id="security-posture-band-heading-1082x0" class="mt-2 text-3xl font-semibold tracking-tight text-foreground sm:text-4xl">What a reviewer will ask, answered first</h2>
    <p class="mt-3 max-w-2xl text-base text-muted-foreground">A wall of certification logos answers none of these. Each figure names its scope, because a control that covers one environment and not the other is the thing a reviewer is looking for.</p>
    <dl class="mt-10 grid grid-cols-1 gap-px overflow-hidden rounded-xl border border-border bg-border sm:grid-cols-2 lg:grid-cols-4">
      <div class="min-w-0 bg-card p-6">
        <dt class="break-words text-sm font-medium text-muted-foreground">Encryption at rest</dt>
        <dd class="mt-2 break-words text-3xl font-semibold tabular-nums tracking-tight text-foreground">AES-256</dd>
        <p class="mt-1 text-sm text-muted-foreground">Every store, including backups and the search index.</p>
      </div>
      <div class="min-w-0 bg-card p-6">
        <dt class="break-words text-sm font-medium text-muted-foreground">Median patch time</dt>
        <dd class="mt-2 break-words text-3xl font-semibold tabular-nums tracking-tight text-foreground">31 h</dd>
        <p class="mt-1 text-sm text-muted-foreground">Critical CVEs, from advisory to production, trailing year.</p>
      </div>
      <div class="min-w-0 bg-card p-6">
        <dt class="break-words text-sm font-medium text-muted-foreground">Data regions</dt>
        <dd class="mt-2 break-words text-3xl font-semibold tabular-nums tracking-tight text-foreground">4</dd>
        <p class="mt-1 text-sm text-muted-foreground">EU, US, UK and AU. Pinned per workspace, never replicated out.</p>
      </div>
      <div class="min-w-0 bg-card p-6">
        <dt class="break-words text-sm font-medium text-muted-foreground">Access reviews</dt>
        <dd class="mt-2 break-words text-3xl font-semibold tabular-nums tracking-tight text-foreground">Quarterly</dd>
        <p class="mt-1 text-sm text-muted-foreground">All production access, logged and exportable.</p>
      </div>
    </dl>
  </div>
</section>
  • This is rendered HTML, not a translation of the React source. The Tailwind classes carry the design and work in any framework.
  • It is one frame: the component in its initial state, with no props applied beyond the defaults.
  • Requires Tailwind, and the design tokens the classes reference (bg-card, text-muted-foreground, and so on). The template ZIPs ship a globals.css that defines them.

What each framework gets across the whole catalog — effects convert properly; this rung is markup.

For AI

The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.

See the prompt

Used in these pages

Want the whole screen instead of this one section? Open a page and copy it entire.

6 more blocks in Stats

All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.

Browse Stats

Shipping one commercially

Copying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.

  • A commercial licence for everything in the catalog
  • Unlimited bundle exports, in Vue, Svelte and Tailwind
  • One payment — no subscription, nothing to renew
Pro — $79 once

More Stats blocks

View category
Open the full page for this block

Hairline Stats Band

A four-up metrics strip with 1px hairline dividers, built from a single gap-px grid so the rules stay crisp on any display.

Stats51 linesNo deps
Open the full page for this block

Stat Cards with Deltas

Metrics carrying the direction they moved, with the good direction declared per stat so a falling churn rate reads as a win — arrow and text, never colour alone.

Stats135 lines1 dep
Open the full page for this block

Stats Beside the Argument

Four figures in a hairline card next to the paragraph making the claim, each carrying an optional source line — for numbers that mean nothing without knowing lower than what, over how long, across how many.

Stats151 lines1 dep
Open the full page for this block

Before-and-After Metric Table

The buyer’s current situation in one column and yours in the next, as a real table with scoped headers — the comparison they are actually making, which a delta against your own past cannot express.

Stats210 lines1 dep
Open the full page for this block

Milestone Timeline

The same measurement taken year after year down a vertical rail, each with the event that explains it — the shape for trajectory, which no snapshot of four numbers can claim.

Stats157 linesNo deps
Open the full page for this block

Benchmark Stat Band

Performance figures with the measurement method printed beside each one, so a sceptical reader can check rather than take them.

Stats121 linesNo deps