You're handing a security vendor your external attack surface. Here's exactly how we protect it — and how we run our own shop. No hand-waving.
Your data is encrypted in transit (TLS) and at rest. No exposure surface left open on our side.
Multi-factor authentication is required for every operation in TRaViS — no single-factor paths, for you or for us.
Role-based, scoped access. Staff access to customer data is minimized, logged, and reviewed.
We assess only domains you own or are authorized to scan. Authorization is part of onboarding, not an afterthought.
We don't store your domain or findings without your consent — and you can request deletion at any time.
Customer data is logically separated per tenant — including for MSSP partners running multi-client coverage.
Our controls are mapped to what your auditors, clients, and regulators care about — questionnaire and reports on request.
Controls mapped to the SOC 2 Trust Services Criteria. Security questionnaire & report available on request.
Aligned with PCI DSS requirements for handling cardholder-data-adjacent environments.
Designed for EU financial entities and NY-regulated institutions — the regimes that don't accept "we didn't know."
Need to see our documents, a completed security questionnaire, or a DPA? Ask our security team →
We're a security company — we'd rather hear it from you than from an attacker. We commit to good-faith review and won't pursue legal action against researchers acting in good faith.
Email security@travisasm.com with details and reproduction steps.
Machine-readable policy: /.well-known/security.txt