Skip to content

Capabilities

See where Valty can price, prove, and prioritize cyber risk today.

Use this map to see what is live, where design partners can shape the product, and what evidence each output needs before it reaches your IC, board, auditor, or insurer.

Base platform + risk reduction modules

Start with the cyber-risk match. Add modules only after the motion is scoped.

Valty Base gives a PE operating team a dollarized cyber-risk view: a modeled loss-exposure range, evidence ledger, and proof pack. Each module is an optional connected workflow, labeled design partner or available through integrations, that shows the evidence required before any reduction is treated as publishable.

Required base

Loss-exposure match

Portfolio exposure, FAIR-style assumptions, board-ready proof, and confidence state. This is the shared risk currency every module attaches to.

Modeled loss rangeEvidence freshnessProof packModule stage

Module stages are claim-reviewed. Dollar reductions are not shown here because they depend on source coverage, portfolio context, remediation scope, and proof confidence.

Capability map

Find the workflow. Check the evidence. Decide what to fund first.

16 of 16 Valty capabilities shown.
Design partnerPublic capability

Adversarial Exposure Validation

Test exploitability and reachability in supported, authorized paths so the financial model can distinguish validated exposure from unvalidated findings.

Proof you can inspect
Exploit-validation proof (no exploit, no report), ATT&CK coverage map, and an attack-path-to-exploited-to-priced bridge
What Valty does not claim
Sanctioned, scoped simulation that validates exploitability. Validated-exposure weighting is a controlled design-partner preview and is not included in decision figures unless explicitly enabled for that workspace. Breach-and-attack simulation and bring-your-own offensive tools are orchestrated as adapters with design partners, not a replacement for your red team or a continuous production exploitation service; fully autonomous penetration testing is on the roadmap, not a shipped capability. Findings become claim-eligible only after they promote into evidence, which is signed where signing keys are provisioned and otherwise hash-chained.
Built for
CISO, security operations, offensive / red-team lead
Design partnerPublic capability

AI Security & Governance

Keep dated AI inventory, authorization, and evidence attached to every review. Route supported material changes and incident cases back to human review, preview and stage policy changes with explicit approval, and map declared versus observed reach across identities, agents, tools, data, and environments. Supported response options, partial outcomes, recovery, same-probe replay, recurrence checks, source health, and uncertainty stay visible.

Proof you can inspect
AI inventory and review workflow, effective-dated revision history, privacy-minimized runtime correlation, supported material-change review queue, policy preview, approval and execution receipts, declared-versus-observed access graph, source-system readback and path-replay record, privacy-minimized incident-case timeline, response-authority and reconciliation record, recovery, replay, and recurrence review record, rollback record, classification drift record, AI governance checklist, human decision trail
What Valty does not claim
Design-partner workflow. Source, change-type, telemetry, reachability, and incident-case coverage remain visible; missing or untrusted signals are not proof that no AI exists, no material change occurred, an incident is closed, or an environment is safe. Routine drafting, retrieval, extraction, questionnaire assistance, scheduling, memory use, and successful workflow execution remain governed AI activity, not an incident or response. Supported policies, access paths, and response options can be previewed and reviewed, but complete live enforcement, authoritative IAM/MCP/RAG/data or provider response changes, durable production case composition, production signing and trust-root custody, long-running recurrence monitoring, outage recovery, and release-specific rollback, path-reduction, or incident-closure proof are still under validation. Partial, degraded, unsigned, unreconciled, unreplayed, or recurrent response is not success or closure. Current public scope does not claim AI-risk pricing, autonomous production response, incident resolution, or safe AI. Regulated AI decisions require human review.
Built for
CISO, AI governance lead
Design partnerPublic capability

AppSec / ASPM

Connect application security findings to reachable, unreachable, or unknown runtime paths, verified fixes, release risk, and proof artifacts.

Proof you can inspect
SARIF finding proof, package/function reachability witness, validated-secret result, fix verification, and release evidence
What Valty does not claim
Incomplete trace or graph evidence remains unknown. Valty does not claim replacement for customer SAST, SCA, CI, or repository enforcement systems.
Built for
Engineering security, AppSec lead
Design partnerPublic capability

CNAPP / CSPM

Follow an identity and permission path to the reachable assets and data, compute the blast radius, identify the smallest access-edge cut set, and attach the remediation to the existing FAIR financial-impact spine.

Proof you can inspect
Identity-path provenance, reachable asset and data set, minimal remediation cut set, cloud finding evidence card, and FAIR impact trace
What Valty does not claim
Design-partner engine. Incomplete identity or permission data is degraded, never assumed safe; native enforcement remains customer-owned.
Built for
Cloud security, CISO
Design partnerPublic capability

Cyber Risk Quantification Software

Compare cyber investments using modeled annual loss, action costs, and a defined budget. Inspect observed, prior-backed, and missing inputs; review the chosen loss objective and the assumptions that could change the recommendation. Evaluate the supported workflow with a real company question before agreeing access and terms.

Proof you can inspect
Actual Valty loss-exposure interface with illustrative data. Review annual loss metrics, input assumptions, evidence sufficiency, and the recorded model version. The public synthetic sample is separate from this capture.
What Valty does not claim
Modeled reduction is not observed savings or a guarantee. Exact metrics, integrations, uncertainty treatment, and execution capabilities depend on the agreed evaluation scope and available product configuration. The sample is not independently calibrated customer evidence.
Built for
PE operating partner, CFO, board
Design partnerPublic capability

Detection & Response

Ingest CISA KEV, MITRE ATT&CK, and ENISA threat intelligence; match it to the organization's assets and posture; and propose a structured Threat, Asset, Method, and Effect scenario for analyst confirmation before promotion.

Proof you can inspect
Threat-source provenance, workspace context, four-part FAIR-aligned draft, analyst lifecycle decision, incident-to-proof trail, and response validation summary
What Valty does not claim
AI‑assisted workflow. Proposed scenarios remain drafts until a human confirms or dismisses them; Valty does not claim to own response execution by default.
Built for
SOC, CISO
Design partnerPublic capability

Exposure Management

Separate reachable, unreachable, and unknown findings with a replayable witness; prioritize the paths that change modeled annual loss; send quantified context to Jira or ServiceNow; and recompute residual risk only after verified closeout evidence returns.

Proof you can inspect
Reachability witness, financially ranked findings table, Jira/ServiceNow remediation record, closeout evidence card, and residual-risk recompute trail
What Valty does not claim
Design-partner workflow. Incomplete trace or graph data remains unknown, and ticket status alone is never treated as closure evidence.
Built for
CISO, security operations
Design partnerPublic capability

Federal / Regulatory

Structure evidence-supported federal readiness packages without implying unearned authorization. Valty ships the underlying catalogs — CMMC Level 2 with all 320 NIST 800-171A assessment objectives plus SPRS scoring and a 180-day POA&M lifecycle, and FedRAMP 20x with 61 KSIs and OSCAL 1.1.2 SSP/SAP/SAR/POA&M generation — so a supplier can assemble a defensible package and see exactly where evidence is missing.

Proof you can inspect
800-171A objective crosswalk, SPRS score view, POA&M with the 180-day clock, OSCAL package generation, and a factual status statement
What Valty does not claim
Valty generates readiness evidence and OSCAL packages; it does not grant an authorization. No authorization or certification claim publishes without recorded claim sign-off, and product coverage is never presented as a company certification.
Built for
Federal supplier, compliance lead
Design partnerPublic capability

GRC / IRM / ERM

Turn framework work into current proof across mapped framework catalogs, with named owners and business-facing risk decisions. Mapping is not certification.

Proof you can inspect
Policy management with approval and e-sign workflows, an auditor portal with PBC request tracking, evidence-freshness monitoring, task and remediation workflows with auto-close, and security-awareness training — surfaced as control evidence, proof-pack excerpts, and audit workflow status.
What Valty does not claim
Does not replace customer auditors, counsel, or required certification bodies. Onboarding is design-partner staged, and some workflow surfaces are flag-gated until live validation evidence is complete.
Built for
CISO, compliance lead
Design partnerPublic capability

Portfolio Operations

Give operating partners one ranked view of which cyber moves change modeled annual loss across the hold period. Show shared vendor and policy-exclusion cascades, additive and diversified totals, unsupported companies, and a hold-period re-underwrite redlined against the last reviewed IC figure.

Proof you can inspect
Guided first baseline, Portfolio rollup, shared-dependency cascade, additive/diversified totals, funding-order queue, IC delta, and board / LP export pack
What Valty does not claim
Portfolio rollup requires a multi-company workspace. Outside-in figures remain unverified and cannot be published as reviewed or IC-final until the evidence upgrade and publication gates pass; unsupported companies are never priced at zero.
Built for
PE operating partner
Design partnerCatalog overview

Supply Chain / TPRM

Package supplier and component evidence into readiness decisions your customers, assessors, and federal buyers can inspect.

Proof you can inspect
Component provenance, readiness areas, submission blockers
What Valty does not claim
Federal and UAS readiness language requires factual status and claim review before deeper publication.
Built for
Supply-chain lead, federal supplier
Design partnerCatalog overview

Trust Center / Audit Proof

Give buyers, auditors, insurers, and assessors a public trust center where proof is current, scoped, and inspectable. Publish security posture, the live subprocessor registry, and evidence status without a sales call, then route deeper artifacts through NDA-gated access requests. Every proof pack and export preview carries method, source, confidence, and freshness on each claim.

Proof you can inspect
Public trust center portal, subprocessor registry, proof-pack export preview, evidence-freshness state, and NDA-gated access requests
What Valty does not claim
The public trust center is live; NDA-gated routing to deeper artifacts is scoped with design partners while audience access controls are finalized.
Built for
Compliance, buyer security
Available through integrationsCatalog overview

Endpoint Awareness

Connect endpoint posture and human-risk to the evidence behind your board and audit claims. Valty ships a built-in security-awareness training module — assign it, track completion, and feed it alongside your endpoint signals into the same evidence model — so training completion and device compliance become sourced, fresh controls that stand behind a board claim rather than a separate spreadsheet.

Proof you can inspect
Security-awareness training completion evidence, endpoint posture card, human-risk summary, and device compliance state
What Valty does not claim
Valty uses endpoint data as evidence through your existing tools; the built-in training module is native, but Valty does not replace your endpoint protection platform.
Built for
IT, security awareness, CISO
Available through integrationsCatalog overview

Zero Trust Assurance

Verify zero-trust posture across the systems you already own, then price the gaps. Valty reads identity, device, network, data, cloud, API, and workload evidence, maps each signal to the control it satisfies across the zero-trust pillars, and shows where coverage is current, stale, or missing — so a zero-trust posture claim becomes per-pillar evidence with a dollar consequence attached, not an assertion.

Proof you can inspect
Per-pillar readiness matrix, cross-control proof card, evidence-freshness state, and the exposure attached to each gap
What Valty does not claim
Valty verifies zero-trust evidence; it does not replace your ZTNA, SASE, NAC, or identity platform.
Built for
CISO, identity lead
Roadmap previewCatalog overview

API Security

Turn API inventory, contracts, and auth posture into risk evidence your security and platform teams can act on.

Proof you can inspect
Design-partner API contract and auth posture evidence pack
What Valty does not claim
Dedicated API-security workflows are not marketed as live until design-partner evidence is validated.
Built for
AppSec, platform engineering
Roadmap previewCatalog overview

Software Assurance / QA

Give engineering and security leaders release evidence they can inspect instead of relying on status claims.

Proof you can inspect
Design-partner release evidence and quality proof pack
What Valty does not claim
Dedicated QA workflows stay in roadmap/design-partner status until customer evidence supports broader claims.
Built for
Engineering, QA, product