Security

A security company, held to a security bar.

We ask you to trust us with your site, so we are clear about how we protect it. Here is how Torlyx handles security.

Encrypted in transit and at rest

All traffic uses modern TLS. Credentials you give us — cloud keys, WAF tokens, scan session headers — are encrypted at rest and never returned by the API.

Least-privilege access

Every connection is scoped to exactly what a scan needs. You choose what Torlyx can see, and you can revoke it any time.

Guarded scanning

Scans run in dedicated worker processes with private-network and cloud-metadata egress blocked, and only ever against sites you've proven you own.

Your data stays yours

We never sell your data or scan results, and we never use them to train models for third parties.

Held to our own bar

Torlyx is built to pass the same checks it runs for you — security headers, TLS, dependency hygiene — and we fix what our own scanner flags.

Responsible disclosure

Found a vulnerability in Torlyx? We welcome reports and will work with you to fix it quickly and safely.

Report a vulnerability

If you believe you have found a security issue in Torlyx, please email us at security@torlyx.com. We investigate every report and will keep you updated as we resolve it.