Tava Health · Domain Security

Tava Health Domain Security

Domain security

TLS, HSTS and DNS posture across every Tava Health host found in this pass. All four hosts serve TLS 1.3 with valid certificates and HSTS at a one-year max-age; the two portal hosts additionally set includeSubDomains. At the DNS layer tavahealth.com publishes SPF and a DMARC policy of quarantine but has no DNSSEC and no CAA record — both are absences, recorded as observed rather than inferred.

Domain security posture for Tava Health, probed live across 4 host(s) and 1 registrable domain(s). 4 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

CompanyHealthcareMental HealthBehavioral HealthTelehealthEmployee BenefitsHealth PlansHIPAADigital HealthCare Delivery

Transport & Host Security

www.tavahealth.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 15 08:32:09 2026 GMT
care.tavahealth.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 12 23:59:59 2026 GMT
app.tavahealth.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 12 23:59:59 2026 GMT
docs.tavahealth.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Nov 18 18:57:58 2026 GMT

Domain (DNS/Email) Security

tavahealth.com
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

tava-health-domain-security.yml Raw ↑
generated: '2026-08-29'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml hosts, extended by hand to the three additional Tava Health
  hosts discovered during contract discovery (client portal, provider portal, developer hub)
hosts:
- host: www.tavahealth.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 15 08:32:09 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  note: Marketing site (Webflow).
- host: care.tavahealth.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec 12 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  server: AmazonS3
  note: Client (member) portal. Static single-page app served from S3; catch-all route answers 200 for
    every path.
- host: app.tavahealth.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec 12 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  server: AmazonS3
  note: Provider/administrative portal ("Harmony"). Static single-page app served from S3.
- host: docs.tavahealth.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Nov 18 18:57:58 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: false
  server: cloudflare
  note: DirectCare developer hub on ReadMe.io behind Cloudflare. Password-gated; sets x-frame-options
    Deny, x-content-type-options nosniff, and a 100-request rate limit header.
domains:
- domain: tavahealth.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: quarantine
  dnssec_note: No DNSKEY record — the zone is not signed.
  caa_note: No CAA record published; any CA may issue for this domain.
  dmarc_note: Policy p=quarantine — deployed and enforcing, short of p=reject.
name: Tava Health domain security
description: TLS, HSTS and DNS posture across every Tava Health host found in this pass. All four hosts
  serve TLS 1.3 with valid certificates and HSTS at a one-year max-age; the two portal hosts additionally
  set includeSubDomains. At the DNS layer tavahealth.com publishes SPF and a DMARC policy of quarantine
  but has no DNSSEC and no CAA record — both are absences, recorded as observed rather than inferred.
hosts_probed: 4

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tava-health-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.