TRaViS is a product of Seron Security, Inc. ("Seron," "we," "us"). This policy explains what personal data we collect, why we collect it, who we share it with, and the choices you have. We collect as little as we can to run the service. We do not sell personal data, and we do not send your attack-surface data to third-party AI providers.
This policy applies to visitors of travisasm.com, to people who contact us or book time with us, to customers and their authorized users of the TRaViS platform (the "Service"), and to the clients of MSP and MSSP partners who deliver TRaViS under their own brand. Seron Security, Inc., 2 Smokey Road, Bow, NH 03304, USA, is the business responsible for this policy.
We act in two different capacities, and your rights differ depending on which one applies.
Where GDPR or UK GDPR applies, our legal bases are: performance of a contract; our legitimate interests in running, securing, and promoting a business-to-business service; your consent for optional cookies and marketing; and compliance with legal obligations. You may withdraw consent at any time without affecting processing that already happened.
TRaViS uses machine-learning models to discover assets, classify findings, and prioritize remediation. Those models run on infrastructure we own and operate. Customer data, including targets, findings, and reports, is not sent to third-party AI providers and is not used to train any third-party model. Model outputs are recommendations for your security team; we do not make decisions that produce legal or similarly significant effects about individuals by automated means.
We do not sell personal data and we do not share it for cross-context behavioral advertising. We share personal data only with:
| Provider | Purpose | Location |
|---|---|---|
| Innovative Scaling Technologies | Hosting of the TRaViS platform and customer environments | United States |
| Cloudflare, Inc. | DNS, CDN, TLS termination, and bot protection for travisasm.com | United States (global edge) |
| Calendly LLC | Meeting scheduling when you book a call | United States |
| Email and CRM providers | Business email, contact management, and customer correspondence | United States |
| Payment processor | Subscription billing and card processing for direct customers | United States |
Customers may request the full sub-processor list with vendor names and may subscribe to change notifications by emailing privacy@travisasm.com.
Nothing non-essential is set until you accept. Your choice is kept in browser storage, not a cookie. With your permission we set two first-party cookies for page-variant testing and campaign attribution. We do not use advertising cookies or third-party analytics. When you use the booking calendar or the contact form's human check, Calendly and Cloudflare may set their own cookies. You can change your choice at any time from the "Cookie settings" link in the footer. Names, purposes, and lifetimes are in the Cookie Policy.
We protect data with encryption in transit and at rest, mandatory multi-factor authentication, least-privilege and logged staff access, and per-customer isolated environments hosted in the United States. Our controls, disclosure program, and incident-response commitments are described on the Trust & Security page. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you without undue delay and within the time the law and your agreement require.
We are a United States company and process data in the United States. If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, your data will be transferred to the United States. Where required we rely on Standard Contractual Clauses or the UK International Data Transfer Addendum, available on request as part of our Data Processing Agreement.
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent. To exercise any of these rights email privacy@travisasm.com. We will verify your identity, respond within the time the applicable law allows (30 days in most cases), and will not discriminate against you for exercising a right. If we decline a request you may appeal by replying to our response.
Under the California Consumer Privacy Act, as amended, you have the right to know what personal information we collect and how we use and disclose it (this policy), to delete it, to correct it, and to opt out of sale or sharing. In the past twelve months we have collected the categories listed in section 3 (identifiers, commercial information, internet activity, professional information, and inferences drawn for campaign attribution). We do not sell or share personal information as those terms are defined in California law, and we do not use or disclose sensitive personal information for purposes that require a right to limit. Because we set nothing non-essential without consent and do not sell or share personal information, there is nothing for a Global Privacy Control signal to opt you out of; we honor it in any case. You may use an authorized agent to make a request; we will ask for proof of authorization.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, New Hampshire, and other states with comprehensive privacy laws have similar rights to access, correct, delete, port, and opt out of targeted advertising, sale, or profiling. We do not engage in targeted advertising, sale, or profiling with legal effect. Requests and appeals go to the address above.
You have the rights described above under GDPR, UK GDPR, and the Swiss FADP, and the right to lodge a complaint with your local supervisory authority. We have not appointed an EU or UK representative; contact us directly.
Every marketing email includes an unsubscribe link, and you can email privacy@travisasm.com to be removed from all outreach. We only send business-to-business communications to work addresses. Opting out of marketing does not stop service notices to active accounts.
TRaViS is a business service. It is not directed to children and we do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
Our site links to partners, the Calendly booking page, and other third-party sites. Their privacy practices are their own. Read their policies before giving them data.
We will update this policy as the Service and the law change and will revise the date at the top. For material changes affecting customers we will give notice by email or in the platform before they take effect.
Privacy questions and requests: privacy@travisasm.com. Post: Seron Security, Inc., Attn: Privacy, 2 Smokey Road, Bow, NH 03304, USA. Phone: 617.855.0005.