Legal

Privacy Policy

Last updated: September 9, 2026

TRaViS is a product of Seron Security, Inc. ("Seron," "we," "us"). This policy explains what personal data we collect, why we collect it, who we share it with, and the choices you have. We collect as little as we can to run the service. We do not sell personal data, and we do not send your attack-surface data to third-party AI providers.

  1. Who this covers
  2. Our two roles
  3. What we collect
  4. How we use it
  5. AI processing
  6. Who we share it with
  7. Cookies
  8. Retention
  9. Security
  10. International transfers
  11. Your rights
  12. Marketing choices
  13. Children
  14. Third-party sites
  15. Changes
  16. Contact

1. Who this covers

This policy applies to visitors of travisasm.com, to people who contact us or book time with us, to customers and their authorized users of the TRaViS platform (the "Service"), and to the clients of MSP and MSSP partners who deliver TRaViS under their own brand. Seron Security, Inc., 2 Smokey Road, Bow, NH 03304, USA, is the business responsible for this policy.

2. Our two roles

We act in two different capacities, and your rights differ depending on which one applies.

  • Controller. For the website, marketing, sales conversations, billing, and the account records of the people who log in to TRaViS, we decide how and why personal data is processed. This policy governs.
  • Processor. For data that our customers load into or generate inside the Service (target domains, discovered assets, findings, exposed credentials, report contents, and any personal data that appears in them), the customer is the controller and we process it only on their instructions under the customer agreement and, where signed, a Data Processing Agreement. If you are an employee of one of our customers and your email address surfaced in a credential-exposure finding, your employer is the party to contact about that data; we will assist them.

3. What we collect

Information you give us

  • Contact and business details when you fill in a form, email us, or book a meeting: name, work email, company, phone, the domain you want assessed, and anything you write in the message.
  • Account details when you become a customer: name, work email, role, authentication data (we require multi-factor authentication), and billing contact information. Card numbers are handled by our payment processor and never touch our servers.
  • Support and correspondence: what you tell us when you contact support, report a security issue, or answer a questionnaire.

Information collected automatically

  • Server and security logs: IP address, user agent, pages requested, timestamps, and referrer. Our CDN and bot-protection provider (Cloudflare) also processes this data to keep the site up and block abuse.
  • Cookies and similar technologies, described in section 7 and in our Cookie Policy.
  • Campaign attribution (which link brought you here, which page variant you saw), only if you allow analytics cookies.

Information generated by the Service

  • The targets you authorize us to scan and everything we discover about them from the public internet: hostnames, IP addresses, certificates, open services, software versions, cloud storage exposure, DNS and mail configuration, and similar.
  • Credential-exposure findings. These may include email addresses, usernames, and indicators that a password associated with an address has appeared in a breach corpus. We store fingerprints and indicators rather than plaintext secrets wherever the finding allows it.
  • Reports, remediation guidance, audit trails, and usage data about how the platform is used.

Information from other sources

  • Business contact details from public professional sources and from partners who refer you, used for business-to-business outreach.
  • End-client information supplied by MSP and MSSP partners who onboard their clients to TRaViS. The partner is responsible for having the right to share it.

4. How we use it

  • To provide, secure, support, and improve the Service and deliver reports and alerts.
  • To respond to your enquiries, schedule calls, run pilots, and manage the commercial relationship, including billing and collections.
  • To send service notices (security advisories, changes to terms, outages) that you cannot opt out of while you have an account.
  • To send product and marketing communications where permitted. You can opt out at any time (section 12).
  • To detect, investigate, and prevent fraud, abuse, and unauthorized scanning.
  • To meet legal, regulatory, tax, and audit obligations and to enforce our agreements.

Where GDPR or UK GDPR applies, our legal bases are: performance of a contract; our legitimate interests in running, securing, and promoting a business-to-business service; your consent for optional cookies and marketing; and compliance with legal obligations. You may withdraw consent at any time without affecting processing that already happened.

5. AI processing

TRaViS uses machine-learning models to discover assets, classify findings, and prioritize remediation. Those models run on infrastructure we own and operate. Customer data, including targets, findings, and reports, is not sent to third-party AI providers and is not used to train any third-party model. Model outputs are recommendations for your security team; we do not make decisions that produce legal or similarly significant effects about individuals by automated means.

6. Who we share it with

We do not sell personal data and we do not share it for cross-context behavioral advertising. We share personal data only with:

  • Service providers (sub-processors) who process data on our behalf under contract and only for the purposes we specify. A current list is below.
  • Your MSP or MSSP partner, if you receive TRaViS through one. The partner sees the findings for the clients it manages.
  • Professional advisers such as lawyers, accountants, auditors, and insurers, under confidentiality.
  • Authorities where the law requires it, or where disclosure is necessary to protect our rights, our customers, or the public. Unless prohibited, we will tell you before we disclose your data in response to a legal demand.
  • A successor in a merger, acquisition, or sale of assets, subject to this policy.
ProviderPurposeLocation
Innovative Scaling TechnologiesHosting of the TRaViS platform and customer environmentsUnited States
Cloudflare, Inc.DNS, CDN, TLS termination, and bot protection for travisasm.comUnited States (global edge)
Calendly LLCMeeting scheduling when you book a callUnited States
Email and CRM providersBusiness email, contact management, and customer correspondenceUnited States
Payment processorSubscription billing and card processing for direct customersUnited States

Customers may request the full sub-processor list with vendor names and may subscribe to change notifications by emailing privacy@travisasm.com.

7. Cookies

Nothing non-essential is set until you accept. Your choice is kept in browser storage, not a cookie. With your permission we set two first-party cookies for page-variant testing and campaign attribution. We do not use advertising cookies or third-party analytics. When you use the booking calendar or the contact form's human check, Calendly and Cloudflare may set their own cookies. You can change your choice at any time from the "Cookie settings" link in the footer. Names, purposes, and lifetimes are in the Cookie Policy.

8. Retention

  • Website logs: kept for a limited period for security and troubleshooting, then deleted or aggregated.
  • Enquiries and sales records: kept while we have a live conversation or a legitimate reason to follow up, then deleted.
  • Customer accounts and Service data: kept for the subscription term. After termination we export your data on request and destroy it within 30 days, except where the law requires longer retention or the data lives in backups that roll off on a fixed schedule.
  • Billing and contract records: kept as long as tax and accounting law requires.

9. Security

We protect data with encryption in transit and at rest, mandatory multi-factor authentication, least-privilege and logged staff access, and per-customer isolated environments hosted in the United States. Our controls, disclosure program, and incident-response commitments are described on the Trust & Security page. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you without undue delay and within the time the law and your agreement require.

10. International transfers

We are a United States company and process data in the United States. If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, your data will be transferred to the United States. Where required we rely on Standard Contractual Clauses or the UK International Data Transfer Addendum, available on request as part of our Data Processing Agreement.

11. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent. To exercise any of these rights email privacy@travisasm.com. We will verify your identity, respond within the time the applicable law allows (30 days in most cases), and will not discriminate against you for exercising a right. If we decline a request you may appeal by replying to our response.

California residents

Under the California Consumer Privacy Act, as amended, you have the right to know what personal information we collect and how we use and disclose it (this policy), to delete it, to correct it, and to opt out of sale or sharing. In the past twelve months we have collected the categories listed in section 3 (identifiers, commercial information, internet activity, professional information, and inferences drawn for campaign attribution). We do not sell or share personal information as those terms are defined in California law, and we do not use or disclose sensitive personal information for purposes that require a right to limit. Because we set nothing non-essential without consent and do not sell or share personal information, there is nothing for a Global Privacy Control signal to opt you out of; we honor it in any case. You may use an authorized agent to make a request; we will ask for proof of authorization.

Other United States residents

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, New Hampshire, and other states with comprehensive privacy laws have similar rights to access, correct, delete, port, and opt out of targeted advertising, sale, or profiling. We do not engage in targeted advertising, sale, or profiling with legal effect. Requests and appeals go to the address above.

EEA, UK, and Swiss residents

You have the rights described above under GDPR, UK GDPR, and the Swiss FADP, and the right to lodge a complaint with your local supervisory authority. We have not appointed an EU or UK representative; contact us directly.

12. Marketing choices

Every marketing email includes an unsubscribe link, and you can email privacy@travisasm.com to be removed from all outreach. We only send business-to-business communications to work addresses. Opting out of marketing does not stop service notices to active accounts.

13. Children

TRaViS is a business service. It is not directed to children and we do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.

14. Third-party sites

Our site links to partners, the Calendly booking page, and other third-party sites. Their privacy practices are their own. Read their policies before giving them data.

15. Changes

We will update this policy as the Service and the law change and will revise the date at the top. For material changes affecting customers we will give notice by email or in the platform before they take effect.

16. Contact

Privacy questions and requests: privacy@travisasm.com. Post: Seron Security, Inc., Attn: Privacy, 2 Smokey Road, Bow, NH 03304, USA. Phone: 617.855.0005.