Sample: Edge score 64, up 6 this monthCore: 12 devices approved, 2 skipped
Free instant check
See what the internet already shows about your domain. No account, no scanning of anything but public records.
We read only public DNS, certificate, and header information, exactly what any visitor's browser receives. We never scan a domain you haven't verified.
Torva Edge and Torva Core
Available now
Torva Edge
Shows what the internet can see.
Scans your internet-facing systems on demand and every month
Finds exposed services, weak encryption, and known vulnerabilities
Shows which logins are protected by MFA
Tracks your score so you can see every change's effect
A one-time audit is out of date the first time someone changes the firewall.
Annual assessmentOne snapshot a year
TorvaEvery month, plus on demand
JanFebMarAprMayJunJulAugSepOctNovDec
When a vendor opens a port for remote support, or a certificate quietly expires, a monthly scan catches it in weeks instead of months. Run an extra scan any time you make a change you want to double-check.
Product tour
Everything you need to find it, fix it, and prove it.
01
Your score, and which way it's heading
One number out of 100, a letter grade, and a trend line. Managers see progress at a glance; IT sees exactly what moved it.
Torva Edge
www.example.comScanned today
D64 / 100
13 findings
1 critical2 high5 medium4 low
Score is up 6 points since the last scan
02
Every finding comes with the fix
See the evidence we found and numbered steps to resolve it, including Windows Server and IIS specifics. No security degree required.
Torva Edge
FindingsCritical first
Remote Desktop (RDP) exposed to the internetCritical
93.184.215.14:3389, found by port scan
3389/tcp open ms-wbt-server
| Product_Version: 10.0.17763
How to fix it
Close port 3389 on the perimeter firewall
Move remote access behind a VPN or RD Gateway with MFA
Review Event ID 4625 for failed outside logins
Outdated TLS versions enabledHigh
No DMARC record for the domainMedium
03
Know which logins are protected
Every internet-facing login, with an honest read on multi-factor authentication. Add a test account and we'll confirm it for certain.
Torva Edge
Internet-facing logins4 found
Patient portalportal.example.com/login, verified with test account
MFA confirmed
SSL VPN portalvpn.example.com, Duo challenge detected
MFA likely
Remote Desktopport 3389, not visible from outside
MFA unknown
SSHport 22, password login only
No MFA detected
04
A report ready for the boardroom, or the auditor
Page one is a two-minute summary for leadership. The pages after it are the fix list for IT. Download a PDF for your records or your cyber insurance renewal.
Torva Edge
TORVA EDGEExternal scan report
www.example.com
Scanned Sep 24, 2026
D
Summary 13 items found. 3 need prompt attention. Since last month, 3 new issues appeared and 2 were fixed.
Severity
Count
Respond
Critical
1
24–72 hours
High
2
2 weeks
Medium
5
30–60 days
05
Inside checks, on devices you choose
Torva Core only scans what you approve. Leave out the lab equipment, the guest Wi-Fi, or anything else, and change your mind any time.
Torva Core, coming next
Core agent: Main officeConnected, outbound only
Servers10.0.1.0/28, 6 devices
Staff workstations10.0.2.0/24, 48 devices
Printers and copiers10.0.3.0/27, 9 devices
Lab equipment10.0.8.0/27, skipped
Guest Wi-Fi192.168.50.0/24, skipped
How it works
Three steps to your first report.
1
Verify your domain
Prove you control it with a DNS record, an uploaded file, or an email to your IT admin address. We only ever scan what you've verified.
DNS recordFileAdmin email
_torva.example.com TXT
"torva-verify=7f3a91c2"
2
Scan from the edge
Edge looks at your systems the way an attacker would: open ports, encryption, web settings, known vulnerabilities, email security, and logins.
✓ Discovering open ports
✓ Testing TLS certificates
✓ Checking web server headers
… Matching known vulnerabilities
3
Fix it and watch the score climb
Work through the fix list, rescan to confirm, and track your score month over month. Add Core when you're ready to look inside.
What Edge checks
Six angles an attacker tries first.
Built on proven, widely used open-source scanning engines, with every result translated into what it means and what to do about it.
Exposed services
Open ports and the services behind them, like Remote Desktop, file sharing, or old admin panels that shouldn't face the internet.
3389/tcp open ms-wbt-server
Encryption
Certificate expiry, outdated TLS versions, and weak ciphers that fail compliance checks and browser standards.
TLS 1.0 offered (deprecated)
Web server settings
Missing security headers, directory listings, version banners, and cookies sent without protection.
Strict-Transport-Security: missing
Known vulnerabilities
Software versions matched against published vulnerability databases, so you know when something needs patching.
Microsoft-IIS/8.5 end of support
Email security
SPF, DKIM, and DMARC records that stop criminals from sending email that looks like it came from you.
_dmarc.example.com no record
Logins and MFA
Every internet-facing login we find, with an honest read on whether multi-factor authentication protects it.
VPN portal MFA likely
Built to be trusted
A security tool should be the safest thing on your network.
We only scan what you've verified
No domain can be scanned until its owner proves control. Free email addresses can't create accounts.
Reports go to the verified owner
Results are also sent to the address that verified the domain, so the real owner always knows a scan ran.
Our scanners are easy to recognize
Scans come from a published list of IP addresses with clear reverse DNS, so your firewall team always knows it's us.
Core connects outbound only
The inside agent never opens a port. It reaches out to us, runs only on devices you approve, and can be paused any time.
Gentle by default
Scans are rate-limited and non-destructive. We look for weaknesses; we never try to exploit them.
Your card stays with Stripe
Payments are processed by Stripe. Torva never sees or stores your card number.
Pricing
Start at the edge. Add the core when you're ready.
Billed monthly. Change plans or cancel anytime from your account.
Questions
Good things to ask a security vendor.
Is this a penetration test?
No. Torva is automated vulnerability scanning. It finds known weaknesses and misconfigurations quickly and repeatedly. A penetration test adds a human who tries to chain weaknesses together, and many organizations use both: Torva every month, a manual test when compliance calls for one.
Could a scan slow down or break my systems?
Scans are rate-limited and non-destructive. We identify weaknesses without exploiting them, and you can schedule scans outside business hours.
How do you prove I'm allowed to scan a domain?
You add a DNS record, upload a small file to your website, or click a link we send to an IT admin address like admin@ or webmaster@ at the domain. Until one of those is done, the domain can't be scanned.
What does Torva Core install inside my network?
A small agent on a machine you choose. It connects outbound to Torva, so no firewall ports are opened, and it scans only the devices and address ranges you approve. You can pause or remove it at any time.
What IP addresses will Edge scans come from?
We publish our scanner addresses so your firewall and monitoring tools can recognize them. You can allowlist them or simply watch for them.
Can I cancel anytime?
Yes. Cancel from your account and your plan stays active until the end of the billing month.
Find out what's showing before someone else does.
Start with an Edge scan today. Your first report shows exactly what the internet can see, and what to fix first.