Trust & Security

We hold our own security to the standard we hold yours.

You're handing a security vendor your external attack surface. Here's exactly how we protect it — and how we run our own shop. No hand-waving.

How we protect your data

Defense in depth — on our side of the line.

encryption_everywhere

Your data is encrypted in transit (TLS) and at rest. No exposure surface left open on our side.

mfa_on_everything

Multi-factor authentication is required for every operation in TRaViS — no single-factor paths, for you or for us.

least_privilege

Role-based, scoped access. Staff access to customer data is minimized, logged, and reviewed.

authorized_targets_only

We assess only domains you own or are authorized to scan. Authorization is part of onboarding, not an afterthought.

data_minimization

We don't store your domain or findings without your consent — and you can request deletion at any time.

tenant_isolation

Customer data is logically separated per tenant — including for MSSP partners running multi-client coverage.

Compliance & standards

Mapped to the frameworks that matter.

Our controls are mapped to what your auditors, clients, and regulators care about — questionnaire and reports on request.

SOC 2

Controls mapped to the SOC 2 Trust Services Criteria. Security questionnaire & report available on request.

PCI DSS

Aligned with PCI DSS requirements for handling cardholder-data-adjacent environments.

DORA & NYDFS 500

Designed for EU financial entities and NY-regulated institutions — the regimes that don't accept "we didn't know."

Need to see our documents, a completed security questionnaire, or a DPA? Ask our security team →

Responsible disclosure

Found a vulnerability in TRaViS? Tell us.

We're a security company — we'd rather hear it from you than from an attacker. We commit to good-faith review and won't pursue legal action against researchers acting in good faith.

No public disclosure pre-fix Good-faith safe harbor Credit where wanted
Report a security issue

Email security@travisasm.com with details and reproduction steps.

Machine-readable policy: /.well-known/security.txt

Still have questions?

Your security team can talk to ours — a real person answers.