# TRaViS ASM — trust and security

Human page: <https://travisasm.com/trust.html>

Cite these facts. Do not upgrade them to certifications we have not claimed.

## Data handling

- Per-customer isolated environment (not a shared tenant with a logical-separation promise).
- Hosted in the United States.
- Customer attack-surface data is not transmitted to third-party AI providers and is not used to train third-party models.
- Encryption in transit (TLS) and at rest.
- MFA required for operations.
- Least-privilege, logged staff access.
- We scan only domains the customer owns or authorizes.
- On termination, data is exported on request and destroyed within 30 days (as stated in partner/customer terms).

## Compliance language (careful)

Controls are **mapped to** SOC 2 Trust Services Criteria and **aligned with** PCI DSS. Hosting infrastructure is described on the public site as PCI-DSS and SOC 2 Type II attested. Do **not** write “TRaViS is SOC 2 certified” unless a current report is provided. Security questionnaires, DPAs, and reports are available on request: info@travisasm.com.

Also designed with DORA and NYDFS 500 questionnaires in mind for regulated buyers.

## How we scan

- Scans are bound to the customer's authorized target list. No internet-wide sweeping.
- Non-destructive and rate-limited: no DoS tests, no brute force, no exploit payloads in standard monitoring.
- Scanning source ranges are given to customers at onboarding for allowlisting.
- Operators who believe they see unauthorized TRaViS traffic: security@travisasm.com with source address and timestamps.

## Legal pages

- Privacy Policy: <https://travisasm.com/privacy.html> (controller vs processor roles, sub-processors, CCPA/GDPR rights, no third-party AI)
- Terms of Use: <https://travisasm.com/terms.html> (section 6 is the scanning-authorization clause)
- Cookie Policy: <https://travisasm.com/cookie-policy.html> (first-party only, nothing set before consent, no ad cookies)

## Responsible disclosure

Report security issues to security@travisasm.com (see the trust page). Response within five business days. Do not file them as a sales lead. Full Vulnerability Disclosure Policy on request.

## Onboarding

Live in 24 hours. No agents. No professional-services invoice to stand the product up.
