Effective August 3, 2026
Stavvy is committed to helping real estate & financial institutions that handle sensitive data maintain a secure digital environment. To ensure you have uninterrupted access to our services, we would like to provide you with the necessary information regarding whitelisting for your webmaster or network administrator.
Whitelisting is a fundamental security practice that allows you to create a list of trusted entities — such as IP addresses and domains — that are explicitly granted permission to access specific resources or services. By whitelisting these trusted entities, you enhance your organization's security posture by actively controlling and restricting access to only approved sources.
Stavvy Domains / IP Addresses to Whitelist
We recommend whitelisting Stavvy's wildcard domain, *.stavvy.com, in any security measures used, such as a network firewall, VPN, or Web proxy. This wildcard domain covers the subdomains used in our web application. It provides access to our internal API. Because our subdomains are subject to change over time, using the wildcard domain ensures you do not need to update whitelists as we introduce new subdomains. Examples of our current subdomains are:
- "connect.stavvy.com"
- "login.stavvy.com"
- "api.connect.stavvy.com"
- "status.stavvy.com"
WebSocket Connections
Some Stavvy features — live meeting updates and real-time document collaboration during signing sessions — use secure WebSocket (WSS) connections to api.connect.stavvy.com. These connections are covered by the wildcard domain above. However, please ensure that your firewall or web proxy permits WebSocket connections (port 443, WSS protocol) to *.stavvy.com. A proxy that allows ordinary HTTPS traffic but blocks WebSocket connections will prevent signing sessions and live meetings from working, even with the domain whitelisted.
Partner Domains / IP Addresses to Whitelist
Twilio
(Unchanged from the current published article — retain the existing Twilio section verbatim at publication: US East Coast and US West Coast IP ranges, Universal Twilio IP Range 35.90.102.128/25, host name global.vss.twilio.com, port 443 WSS, and the Video Diagnostics guidance. See also the internal Twilio Video page.)
Google Cloud Storage: Document Storage and Delivery
Stavvy uses Google Cloud Storage, part of Google Cloud Platform, to securely store and deliver documents. When you view or download a document in Stavvy — such as a loan document, a signed and certified file, or a lender logo — your browser retrieves the file directly from Google Cloud Storage using a time-limited, cryptographically signed link. These downloads do not pass through *.stavvy.com, so Google Cloud Storage must be reachable from your network in addition to Stavvy's own domains. If it is blocked, users will be able to log in but documents will fail to load or download.
We recommend whitelisting the following domains:
-
storage.googleapis.com— all Stavvy document and asset links use this host -
*.storage.googleapis.com— optional but recommended, to future-proof against alternative Google Cloud Storage link formats
Port and Protocol: 443 HTTPS
Google does not publish fixed IP addresses for storage.googleapis.com; the service is fronted by Google's global edge network and its addresses rotate. We therefore recommend whitelisting by domain name (hostname/SNI) rather than by IP address. If your firewall supports only IP-based rules, Google publishes its full address ranges at https://www.gstatic.com/ipranges/goog.json, but be aware this list is large and changes over time, so it must be refreshed periodically.
Note for networks using TLS/SSL inspection or filtering proxies: Stavvy document links are signed URLs — the signature is carried in the link's query string, and any proxy that rewrites the URL, strips query parameters, or re-signs the request will cause downloads to fail with an "Access Denied" (403) error. If your organization uses a TLS-inspecting proxy, we recommend exempting storage.googleapis.com from inspection.
LaunchDarkly: Feature Management
Stavvy uses LaunchDarkly, a trusted feature-management provider, to control the rollout of new features. The Stavvy application connects to LaunchDarkly from your browser to determine which features are enabled for your organization and to receive updates in real time. If LaunchDarkly is blocked, some features may be unavailable or behave inconsistently for your users.
We recommend whitelisting the following domains:
app.launchdarkly.comclientstream.launchdarkly.comevents.launchdarkly.com
Port and Protocol: 443 HTTPS. clientstream.launchdarkly.com uses long-lived streaming (Server-Sent Events) connections — please ensure your proxy does not buffer or terminate long-lived HTTPS connections to this host.
LaunchDarkly publishes its current IP addresses at https://app.launchdarkly.com/api/v2/public-ip-list, but we recommend whitelisting by domain name.
Google Maps: Address Lookup
Stavvy uses the Google Maps Platform to provide address autocomplete and validation when scheduling meetings. If these domains are blocked, users can still type addresses manually, but address suggestions and validation will not work.
We recommend whitelisting the following domains:
maps.googleapis.commaps.gstatic.com
Port and Protocol: 443 HTTPS
Google Fonts: Application Typography
Stavvy loads its user-interface and signature-style fonts from Google Fonts. If these domains are blocked, the application remains fully functional, but text and signatures will display in fallback system fonts.
We recommend whitelisting the following domains:
fonts.googleapis.comfonts.gstatic.com
Port and Protocol: 443 HTTPS
Zendesk: In-App Support
Stavvy's in-app Help widget and live chat are powered by Zendesk. If these domains are blocked, the application remains fully functional, but users will not be able to open the Help widget or start a chat with our Support team from within Stavvy.
We recommend whitelisting the following domains:
static.zdassets.comekr.zdassets.comstavvyhelp.zendesk.com
Port and Protocol: 443 HTTPS
Comments
0 comments
Article is closed for comments.