Truvo Free Tools

Free security tools that speak the language of your audit

Check your domain, score your program, or look up a control. Every result names the SOC 2 or ISO 27001 control it relates to, so you know which audit question a fix answers. Free to use.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.

Connect on LinkedIn

Check your domain

One full scan, or the single check you need. Each result names the SOC 2 and ISO 27001 control it relates to.

Full scan

Domain security scan

Scan any domain for SPF, DMARC, DNS, TLS, security headers and subdomains in one pass. Graded A to F, each finding mapped to the SOC 2 and ISO 27001 control it supports.

SOC 2 ISO 27001
Full scan
Scan a domain →
Check

MX record lookup

Look up the MX records for any domain, see redundancy and priority, and which controls depend on them.

SOC 2 CC6.6 ISO 27001 A.8.14
Check
Run the lookup →
Check

DNS lookup and hygiene check

Query A, MX, TXT, CAA and nameserver records, check DNSSEC, and see nameserver redundancy.

SOC 2 CC6.6 ISO 27001 A.8.20
Check
Run the lookup →
Check

SPF record checker

Validate your SPF record, catch lookup-limit and syntax problems, and see whether spoofed mail can pass as you.

SOC 2 CC6.7 ISO 27001 A.5.14
Check
Check SPF →
Check

DMARC record checker

Check whether your DMARC record exists, whether the policy enforces or only monitors, and whether reporting is set up.

SOC 2 CC6.7 ISO 27001 A.8.23
Check
Check DMARC →
Check

SSL and TLS checker

Test HTTPS reachability, the HTTP to HTTPS redirect, and HSTS strength for any domain.

SOC 2 CC6.1 ISO 27001 A.8.24
Check
Check TLS →
Check

HTTP security headers checker

Check CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy on any site.

SOC 2 CC7.1 ISO 27001 A.8.9
Check
Check headers →
Check

Subdomain finder

Enumerate subdomains from Certificate Transparency logs and spot staging or legacy hosts you forgot about.

SOC 2 CC7.1 ISO 27001 A.8.8
Check
Find subdomains →

How these tools work

The domain scan reads public data only: DNS records, TLS configuration, response headers and Certificate Transparency logs. Nothing touches your systems. The scorecards are self-assessments scored against the framework's own requirements. Each result names the SOC 2 or ISO 27001 control it relates to.

Turn these findings into an audit-ready program

The tools show you where you stand. When you are ready to close the gaps and carry the evidence into a SOC 2 or ISO 27001 audit, that is what we do.

Free tools: frequently asked questions

Yes. Every tool on this page is free to use. The domain scan needs no signup: you enter a domain and see the full result. The scorecards and the framework explorer are free as well.

Each finding is tied to the SOC 2 Trust Services Criteria and the ISO 27001:2022 Annex A control it supports. An SPF or DMARC result maps to SOC 2 CC6.7 and ISO 27001 A.5.14, for example, so you can see which audit requirement the fix addresses.

The domain scan reads publicly observable data such as DNS records, TLS configuration and Certificate Transparency logs, and shows the result to you directly. The scorecards keep your answers in your browser session. No tool on this page requires an email address to show a result.