How we protect your data
- Passwords are stored only as bcrypt hashes, never in plain text.
- All traffic is encrypted with modern TLS. Payment card details go directly to Stripe and never touch our servers.
- Scan results and account data are access-controlled and kept only as long as your account is active.
- Our own marketing site is static, with no database or admin login to attack, and we scan our own systems with Torva every month.
How our scanning behaves
- We only scan verified domains. Paid scans run only after you prove you control the domain. The free instant check reads public records only and performs no active scanning.
- Our scanners are recognizable. Scans come from a published list of IP addresses with clear reverse DNS, so your firewall and monitoring teams always know it's us.
- We're gentle by design. Scans are rate-limited and non-destructive. We look for weaknesses; we never exploit them.
- Torva Core connects outbound only and scans only the internal devices you approve.
Our scanner IP addresses
Add these to your allowlist so scans aren't blocked, and so you can recognize legitimate Torva activity in your logs:
[Your scanner IP addresses will be listed here at launch]
scanner1.torvasecurity.com
scanner2.torvasecurity.com
Reporting a vulnerability in Torva
If you believe you've found a security issue in Torva itself, please tell us. Email [email protected] with the details and steps to reproduce. We'll acknowledge your report, keep you updated, and we won't pursue researchers who act in good faith and avoid privacy violations or service disruption.
This contact is also published in our security.txt file.
A note on honesty. Torva's automated scanning finds known weaknesses and misconfigurations. It is not a manual penetration test and does not guarantee a system is free of vulnerabilities.