Truvo Free Tools
Free security tools that speak the language of your audit
Check your domain, score your program, or look up a control. Every result names the SOC 2 or ISO 27001 control it relates to, so you know which audit question a fix answers. Free to use.
Ali Aleali, CISSP, CCSP
Co-Founder & Principal Consultant
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.
Connect on LinkedInCheck your domain
One full scan, or the single check you need. Each result names the SOC 2 and ISO 27001 control it relates to.
Domain security scan
Scan any domain for SPF, DMARC, DNS, TLS, security headers and subdomains in one pass. Graded A to F, each finding mapped to the SOC 2 and ISO 27001 control it supports.
MX record lookup
Look up the MX records for any domain, see redundancy and priority, and which controls depend on them.
DNS lookup and hygiene check
Query A, MX, TXT, CAA and nameserver records, check DNSSEC, and see nameserver redundancy.
SPF record checker
Validate your SPF record, catch lookup-limit and syntax problems, and see whether spoofed mail can pass as you.
DMARC record checker
Check whether your DMARC record exists, whether the policy enforces or only monitors, and whether reporting is set up.
SSL and TLS checker
Test HTTPS reachability, the HTTP to HTTPS redirect, and HSTS strength for any domain.
HTTP security headers checker
Check CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy on any site.
Subdomain finder
Enumerate subdomains from Certificate Transparency logs and spot staging or legacy hosts you forgot about.
Score your program and look up controls
Readiness scorecards for each framework, a finder for the one to pursue first, and a control crosswalk.
SOC 2 readiness assessment
Score your SOC 2 program in about five minutes. See which Trust Services Criteria you already cover and where the gaps are.
Security maturity assessment
Rate your security program across the capabilities an effective program is built from, and see where to invest next.
ISO 27001 gap analysis
Check where your ISMS stands against the ISO 27001:2022 clauses and Annex A controls before you commit to an audit date.
ISO 42001 readiness assessment
Find out whether your AI management system meets the ISO 42001 requirements, and which gaps to close first.
Framework finder
Answer a few questions about your customers, data and contracts, and get the framework to pursue first.
FEX: framework explorer
Browse SOC 2 and ITSP.10.171 controls side by side, with plain-language descriptions and evidence examples. ISO 27001 is being added.
How these tools work
The domain scan reads public data only: DNS records, TLS configuration, response headers and Certificate Transparency logs. Nothing touches your systems. The scorecards are self-assessments scored against the framework's own requirements. Each result names the SOC 2 or ISO 27001 control it relates to.
Turn these findings into an audit-ready program
The tools show you where you stand. When you are ready to close the gaps and carry the evidence into a SOC 2 or ISO 27001 audit, that is what we do.
Free tools: frequently asked questions
Yes. Every tool on this page is free to use. The domain scan needs no signup: you enter a domain and see the full result. The scorecards and the framework explorer are free as well.
Each finding is tied to the SOC 2 Trust Services Criteria and the ISO 27001:2022 Annex A control it supports. An SPF or DMARC result maps to SOC 2 CC6.7 and ISO 27001 A.5.14, for example, so you can see which audit requirement the fix addresses.
The domain scan reads publicly observable data such as DNS records, TLS configuration and Certificate Transparency logs, and shows the result to you directly. The scorecards keep your answers in your browser session. No tool on this page requires an email address to show a result.