On watch, edge to core.

Edge shows what the internet can see. Core checks what's behind the firewall, on devices you choose.

Plans from $29 a month. Cancel anytime.

Sample: Edge score 64, up 6 this month Core: 12 devices approved, 2 skipped

Free instant check

See what the internet already shows about your domain. No account, no scanning of anything but public records.

We read only public DNS, certificate, and header information, exactly what any visitor's browser receives. We never scan a domain you haven't verified.

Torva Edge and Torva Core

Available now

Torva Edge

Shows what the internet can see.

  • Scans your internet-facing systems on demand and every month
  • Finds exposed services, weak encryption, and known vulnerabilities
  • Shows which logins are protected by MFA
  • Tracks your score so you can see every change's effect
Start with Edge
Coming next

Torva Core

Checks what's behind the firewall, on devices you choose.

  • A small agent inside your network finds what attackers look for once they're in
  • You approve exactly which devices and address ranges it may scan
  • Connects outbound only, so there's no new hole in your firewall
  • Pause or remove it any time from your dashboard
Get Edge + Core

Why monthly

A one-time audit is out of date the first time someone changes the firewall.

Annual assessmentOne snapshot a year

TorvaEvery month, plus on demand

When a vendor opens a port for remote support, or a certificate quietly expires, a monthly scan catches it in weeks instead of months. Run an extra scan any time you make a change you want to double-check.

Product tour

Everything you need to find it, fix it, and prove it.

01

Your score, and which way it's heading

One number out of 100, a letter grade, and a trend line. Managers see progress at a glance; IT sees exactly what moved it.

Torva Edge
02

Every finding comes with the fix

See the evidence we found and numbered steps to resolve it, including Windows Server and IIS specifics. No security degree required.

Torva Edge
03

Know which logins are protected

Every internet-facing login, with an honest read on multi-factor authentication. Add a test account and we'll confirm it for certain.

Torva Edge
04

A report ready for the boardroom, or the auditor

Page one is a two-minute summary for leadership. The pages after it are the fix list for IT. Download a PDF for your records or your cyber insurance renewal.

Torva Edge
05

Inside checks, on devices you choose

Torva Core only scans what you approve. Leave out the lab equipment, the guest Wi-Fi, or anything else, and change your mind any time.

Torva Core, coming next

How it works

Three steps to your first report.

1

Verify your domain

Prove you control it with a DNS record, an uploaded file, or an email to your IT admin address. We only ever scan what you've verified.

DNS recordFileAdmin email
_torva.example.com TXT "torva-verify=7f3a91c2"
2

Scan from the edge

Edge looks at your systems the way an attacker would: open ports, encryption, web settings, known vulnerabilities, email security, and logins.

3

Fix it and watch the score climb

Work through the fix list, rescan to confirm, and track your score month over month. Add Core when you're ready to look inside.

What Edge checks

Six angles an attacker tries first.

Built on proven, widely used open-source scanning engines, with every result translated into what it means and what to do about it.

Exposed services

Open ports and the services behind them, like Remote Desktop, file sharing, or old admin panels that shouldn't face the internet.

3389/tcp open ms-wbt-server

Encryption

Certificate expiry, outdated TLS versions, and weak ciphers that fail compliance checks and browser standards.

TLS 1.0 offered (deprecated)

Web server settings

Missing security headers, directory listings, version banners, and cookies sent without protection.

Strict-Transport-Security: missing

Known vulnerabilities

Software versions matched against published vulnerability databases, so you know when something needs patching.

Microsoft-IIS/8.5 end of support

Email security

SPF, DKIM, and DMARC records that stop criminals from sending email that looks like it came from you.

_dmarc.example.com no record

Logins and MFA

Every internet-facing login we find, with an honest read on whether multi-factor authentication protects it.

VPN portal MFA likely

Built to be trusted

A security tool should be the safest thing on your network.

We only scan what you've verified

No domain can be scanned until its owner proves control. Free email addresses can't create accounts.

Reports go to the verified owner

Results are also sent to the address that verified the domain, so the real owner always knows a scan ran.

Our scanners are easy to recognize

Scans come from a published list of IP addresses with clear reverse DNS, so your firewall team always knows it's us.

Core connects outbound only

The inside agent never opens a port. It reaches out to us, runs only on devices you approve, and can be paused any time.

Gentle by default

Scans are rate-limited and non-destructive. We look for weaknesses; we never try to exploit them.

Your card stays with Stripe

Payments are processed by Stripe. Torva never sees or stores your card number.

Pricing

Start at the edge. Add the core when you're ready.

Torva Edge

Starter

One website or office, checked every month.

$29 /month
  • 1 verified domain
  • Automatic monthly scan
  • PDF report with fix steps
  • Change alerts by email
Choose Edge Starter
Torva Edge

Pro

For IT teams who want to check every change.

$79 /month
  • Up to 5 verified domains
  • On-demand scans anytime
  • Monthly scheduled scans
  • Score history and trend reports
Choose Edge Pro
Torva Edge + Core

Edge + Core

Outside and inside, for organizations with more at stake.

$199 /month
  • Everything in Edge Pro
  • Up to 10 verified domains
  • MFA confirmation with test accounts
  • Torva Core inside-network agent (coming next)
Choose Edge + Core

Billed monthly. Change plans or cancel anytime from your account.

Questions

Good things to ask a security vendor.

Is this a penetration test?

No. Torva is automated vulnerability scanning. It finds known weaknesses and misconfigurations quickly and repeatedly. A penetration test adds a human who tries to chain weaknesses together, and many organizations use both: Torva every month, a manual test when compliance calls for one.

Could a scan slow down or break my systems?

Scans are rate-limited and non-destructive. We identify weaknesses without exploiting them, and you can schedule scans outside business hours.

How do you prove I'm allowed to scan a domain?

You add a DNS record, upload a small file to your website, or click a link we send to an IT admin address like admin@ or webmaster@ at the domain. Until one of those is done, the domain can't be scanned.

What does Torva Core install inside my network?

A small agent on a machine you choose. It connects outbound to Torva, so no firewall ports are opened, and it scans only the devices and address ranges you approve. You can pause or remove it at any time.

What IP addresses will Edge scans come from?

We publish our scanner addresses so your firewall and monitoring tools can recognize them. You can allowlist them or simply watch for them.

Can I cancel anytime?

Yes. Cancel from your account and your plan stays active until the end of the billing month.

Find out what's showing before someone else does.

Start with an Edge scan today. Your first report shows exactly what the internet can see, and what to fix first.

Start with Edge