Skip to main content
Traversal maintains robust controls across access, data handling, and system operations. Security is a core design principle, not an add-on.

Security certifications

Traversal maintains a SOC 2 Type II attestation, aligns with GDPR and HIPAA requirements, and undergoes regular third-party penetration testing.

Traversal Trust Center

Request compliance reports, review security documentation, and find more information about Traversal’s certifications.

Security-first architecture

Traversal is built from the ground up with security as a core design principle.
Traversal deploys no sidecars or background processes in your environment. There is nothing running in your infrastructure on Traversal’s behalf.
Traversal cannot modify your systems or data. All integrations require read-only access only — no write privileges to your data stores or code.
Traversal does not rely on brittle integrations or sensitive structural dependencies. There is no schema configuration required.
Traversal avoids hard-coded prompts or hidden logic that can introduce risk or unpredictable behavior.

Network allowlisting

If your network policies or firewalls require allowlisting of external IP addresses, the relevant IPs depend on how Traversal connects to your environment.
These IP addresses are expected to remain stable, but may change due to infrastructure maintenance operations. Traversal does not guarantee IP address permanence.

Direct integrations

When Traversal’s SaaS environment connects directly to your integrated services (not through the Traversal Connector), it uses the following IP addresses: Add these to your service-side allowlists.

Traversal Connector

When the Traversal Connector is deployed in your environment to reach Traversal’s SaaS, it makes outbound connections to two destinations: it connects to edge.traversal.com, and it exports its own telemetry to telemetry.traversal.com. If your environment restricts egress traffic, allowlist the IP addresses for both. edge.traversal.com: telemetry.traversal.com:
Telemetry egress uses port 4317 by default. If you restrict egress by port as well as by address, allow the port named by the telemetry endpoint your deployment is configured with.

Traversal Processor

When the Traversal Processor is deployed in your environment to reach Traversal’s SaaS, it makes outbound connections to two destinations: it sends data to ingest.traversal.com, and it exports its own telemetry to telemetry.traversal.com. If your environment restricts egress traffic, allowlist the IP addresses for both. ingest.traversal.com: telemetry.traversal.com:
Telemetry egress uses port 4317 by default. If you restrict egress by port as well as by address, allow the port named by the telemetry endpoint your deployment is configured with.
For single-tenant SaaS and BYOC deployments, these IPs do not apply — the Traversal Connector and Processor reach the Traversal control plane within your dedicated deployment instead.

Data privacy

Customer data is not used for cross-customer training, model improvement, or service optimization. Any data processing is limited to in-context use for the originating customer only. All customer data is protected through strict isolation, access controls, and privacy safeguards. For more detail, see the Data privacy page.

Contact security

For detailed security documentation, compliance reports, or to discuss your specific requirements, contact the Traversal security team at security@traversal.com.