You are handing a security vendor your external attack surface. Here is exactly how we protect it, where it lives, who can touch it, and what we do when something goes wrong. No hand-waving. Where we do not hold a certification, we say so.
TLS for every connection in and out. Encryption at rest for stored findings, reports, and backups. Keys are managed by us, not by a shared SaaS layer.
Multi-factor authentication is mandatory for every user and every operation in TRaViS. There is no single-factor path, for you or for us, and it cannot be switched off.
Role-based, scoped access. Staff access to customer data is limited to the people who support you, is logged, and is reviewed. The same rule applies to our AI agents: they get the minimum access the task needs.
Each customer runs in its own isolated environment, not a shared tenant with a logical-separation promise. A problem in one environment cannot reach another. Partners get the same isolation per client.
We assess only domains and assets you own or are authorized in writing to have assessed. Authorization is captured at onboarding and is a condition of our Terms, not an afterthought.
We keep what the service needs and nothing more. Exposed credentials are stored as fingerprints and indicators, not plaintext secrets, wherever the finding allows it. You can request deletion at any time.
The platform and every US customer environment run in the United States on infrastructure operated by Innovative Scaling Technologies, a US-based, veteran-owned provider whose facilities hold their own SOC 2 Type II and PCI DSS attestations. Your data does not leave the country to be processed.
Our discovery and prioritization models run on GPUs and servers we own and operate. Customer targets, findings, and reports are never sent to OpenAI, Anthropic, Google, or any other third-party AI provider, and are never used to train anyone else's model. That was a deliberate design decision, made before it was fashionable.
The vendors that touch personal data are listed in our Privacy Policy. Customers can request the full list with contract details and subscribe to change notices. No one ever receives your attack-surface data.
If you run infrastructure and want to know what TRaViS traffic looks like from your side, this is the section for you.
Scans are bound to the target list a customer authorizes. We do not sweep the internet, and we do not add assets to your scope without telling you. Discovery expands from what you gave us and shows you the trail.
Our checks are read-only where the protocol allows it and are throttled to stay under normal traffic patterns. We do not run denial-of-service tests, brute-force logins, or exploit payloads against production systems.
Customers can receive our scanning source ranges at onboarding so security teams can allowlist or annotate our traffic. If you operate a system and believe you are seeing unauthorized TRaViS traffic, email security@travisasm.com with the source address and timestamps and we will investigate and respond.
Our controls are mapped to what your auditors, clients, and regulators care about. "Mapped to" and "aligned with" mean exactly that. We will tell you the day it becomes "certified."
TRaViS controls are mapped to the SOC 2 Trust Services Criteria. Our hosting provider holds a SOC 2 Type II report. Completed security questionnaire available on request.
Aligned with PCI DSS requirements for environments adjacent to cardholder data. Hosting infrastructure is PCI DSS attested.
Built by a team with a compliance-first background in DFARS and CMMC work. Controls are mapped to NIST CSF and 800-53, and reports are structured to feed evidence for your own assessments.
Designed for EU financial entities and New York regulated institutions, the regimes that do not accept "we didn't know." Our questionnaire answers speak their language.
A Data Processing Agreement with Standard Contractual Clauses is available for customers who need one. See our Privacy Policy for how we handle personal data and honor rights requests.
Security questionnaire, Data Processing Agreement, Service Level Agreement, Vulnerability Disclosure Policy, Breach Notification Policy, and sub-processor list. Ask and we send them; no NDA theater for the basics.
Need documents, a completed questionnaire, or a DPA? Ask our security team →
99.9% uptime commitment under the Service Level Agreement in our Master Services Agreement, with service credits if we miss it. Backups are encrypted and tested. Because each customer environment is isolated, an incident in one does not become an outage for all.
We maintain a written incident-response and breach-notification policy. If an incident affects your data, we notify you without undue delay, within the window your agreement specifies and never later than the law requires, with what we know, what we are doing, and what we think you should do.
Changes to the platform go through review and testing before release. We patch our own exposure with the same urgency we tell you to patch yours, and we run TRaViS against TRaViS.
Staff and contractors with access to customer data are bound by confidentiality, complete security training, and lose access the day their role ends. Access is granted per role, not per person.
Live in 24 hours. Nothing to install inside your network, no agent with privileged access, no professional-services invoice to stand the product up. Our footprint in your environment is zero.
If/When you leave, you get your data exported on request and we destroy it within 30 days, backups included as they expire. We confirm destruction in writing if you ask.We will never hold your data hostage.
We are a security company. We would rather hear it from you than from an attacker. We commit to good-faith review, a response within five business days, and we will not pursue legal action against researchers acting in good faith. Our full Vulnerability Disclosure Policy is available on request.
Email security@travisasm.com with details and reproduction steps.
Machine-readable policy: /security.txt