Skip to content

Capabilities

See where Valty can price, prove, and prioritize cyber risk today.

Use this map to see what is live, where design partners can shape the product, and what evidence each output needs before it reaches your IC, board, auditor, or insurer.

Map Valty to your portfolio

Base platform + risk reduction modules

Start with the cyber-risk match. Turn on modules to move the number.

Valty Base gives a PE operating team the dollarized cyber-risk view: EBITDA-at-risk, evidence ledger, and proof pack. Each module is an optional control plane that models how much EBITDA-at-risk it can remove, then shows the evidence required to prove that reduction.

Required base

Security EBITDA match

Portfolio exposure, FAIR-style assumptions, board-ready proof, and confidence state. This is the shared risk currency every module attaches to.

EBITDA-at-riskEvidence freshnessProof packModule ROI

Dollar movements are illustrative decision-support examples. Actual before/after ranges depend on source coverage, portfolio context, remediation scope, and proof confidence.

Capability map

Find the workflow. Check the evidence. Decide what to fund first.

16 of 16 Valty capabilities shown.
LivePublic / indexed

Cyber Risk Quantification

Translate verified exposure into decision-support financial estimates with visible assumptions. The engine underneath is a real seeded Monte Carlo implementation, not a spreadsheet — a compound collective-risk loss model with extreme-value (EVT/GPD) tail fitting, Student-t copula correlation, paired common-random-numbers to isolate the effect of a single control change, quantile standard errors, and backtesting. These are engine capabilities applied per model, and every output stays a decision-support estimate with its method and confidence visible.

Proof you can inspect
EBITDA bridge, P10/base/P90 confidence band with quantile standard errors, source citations, visible FAIR assumptions, and control-delta comparison
What Valty does not claim
Decision-support estimate only; not actuarial, insurance, accounting, legal, or investment advice.
Built for
PE operating partner, CFO, board
LivePublic / indexed

GRC / IRM / ERM

Turn framework work into current proof across 30+ framework catalogs and 2,700+ source-cited controls, with named owners and business-facing risk decisions.

Proof you can inspect
Policy management with approval and e-sign workflows, an auditor portal with PBC request tracking, evidence-freshness monitoring, task and remediation workflows with auto-close, and security-awareness training — surfaced as control evidence, proof-pack excerpts, and audit workflow status.
What Valty does not claim
Does not replace customer auditors, counsel, or required certification bodies. Onboarding is design-partner staged, and some workflow surfaces are flag-gated until live validation evidence is complete.
Built for
CISO, compliance lead
LivePublic / indexed

Portfolio Operations

Give operating partners one ranked view of which cyber moves change portfolio value across the hold period. Aggregate EBITDA-at-risk across every portfolio company, rank remediation by dollars recovered per dollar spent, and carry the same risk currency from deal desk and 100-day plan through quarterly LP and board reporting — so capital goes to the company and the single move that recovers the most value first.

Proof you can inspect
Portfolio command center rollup, per-portco EBITDA-at-risk ranking, remediation ROI queue, and board / LP export pack
What Valty does not claim
Future lifecycle depth is labeled by stage until product proof exists for each operating motion; portfolio rollup requires multi-company tenant setup.
Built for
PE operating partner
LivePublic / catalog-only

Trust Center / Audit Proof

Give buyers, auditors, insurers, and assessors a public trust center where proof is current, scoped, and inspectable. Publish security posture, the live subprocessor registry, and evidence status without a sales call, then route deeper artifacts through NDA-gated access requests. Every proof pack and export preview carries method, source, confidence, and freshness on each claim.

Proof you can inspect
Public trust center portal, subprocessor registry, proof-pack export preview, evidence-freshness state, and NDA-gated access requests
What Valty does not claim
The public trust center is live; NDA-gated routing to deeper artifacts is scoped with design partners while audience access controls are finalized.
Built for
Compliance, buyer security
Design partnerPublic / indexed

Adversarial Exposure Validation

Prove which exposures are actually exploitable, so the risk you price and remediate is the risk that is real.

Proof you can inspect
Exploit-validation proof (no exploit, no report), ATT&CK coverage map, and an attack-path-to-exploited-to-priced bridge
What Valty does not claim
Sanctioned, scoped simulation that validates exploitability. Breach-and-attack simulation and bring-your-own offensive tools are orchestrated as adapters with design partners, not a replacement for your red team or a continuous production exploitation service; fully autonomous penetration testing is on the roadmap, not a shipped capability. Findings become claim-eligible only after they promote into evidence, which is signed where signing keys are provisioned and otherwise hash-chained.
Built for
CISO, security operations, offensive / red-team lead
Design partnerPublic / indexed

AI Security & Governance

Put authorization, financial thresholds, and evidence around AI systems and autonomous agents.

Proof you can inspect
Agent authorization gate, AI red-team result, AI governance checklist, evidence trail
What Valty does not claim
EU AI Act and regulated AI claims require claim review before publication.
Built for
CISO, AI governance lead
Design partnerPublic / indexed

AppSec / ASPM

Connect application security findings to verified fixes, release risk, and proof artifacts.

Proof you can inspect
SARIF finding proof, validated-secret result, fix verification, release evidence
What Valty does not claim
Does not claim replacement for customer SAST, SCA, CI, or repository enforcement systems.
Built for
Engineering security, AppSec lead
Design partnerPublic / indexed

Exposure Management

Prioritize the findings that change enterprise value, and capture closure evidence with design partners when the work is done.

Proof you can inspect
Findings table, remediation queue, and a design-partner closure-evidence card
What Valty does not claim
Advanced exposure-management depth — including automatic promotion of closed findings into a closure-evidence card — stays design-partner only until live validation evidence is complete.
Built for
CISO, security operations
Design partnerPublic / indexed

Federal / Regulatory

Structure evidence-supported federal readiness packages without implying unearned authorization. Valty ships the underlying catalogs — CMMC Level 2 with all 320 NIST 800-171A assessment objectives plus SPRS scoring and a 180-day POA&M lifecycle, and FedRAMP 20x with 61 KSIs and OSCAL 1.1.2 SSP/SAP/SAR/POA&M generation — so a supplier can assemble a defensible package and see exactly where evidence is missing.

Proof you can inspect
800-171A objective crosswalk, SPRS score view, POA&M with the 180-day clock, OSCAL package generation, and a factual status statement
What Valty does not claim
Valty generates readiness evidence and OSCAL packages; it does not grant an authorization. No authorization or certification claim publishes without recorded claim sign-off, and product coverage is never presented as a company certification.
Built for
Federal supplier, compliance lead
Design partnerPublic / catalog-only

Supply Chain / TPRM

Package supplier and component evidence into readiness decisions your customers, assessors, and federal buyers can inspect.

Proof you can inspect
Component provenance, readiness areas, submission blockers
What Valty does not claim
Federal and UAS readiness language requires factual status and claim review before deeper publication.
Built for
Supply-chain lead, federal supplier
Available through integrationsPublic / catalog-only

CNAPP / CSPM

Convert cloud security source signals into ranked decisions and proof-backed remediation.

Proof you can inspect
Cloud finding evidence card, IaC drift-to-fix proof, exposure graph summary
What Valty does not claim
Native cloud enforcement remains customer-owned unless a specific integration proves otherwise.
Built for
Cloud security, CISO
Available through integrationsPublic / catalog-only

Detection & Response

Tie detection and response work to proof-backed closure and business impact.

Proof you can inspect
Incident-to-proof trail, ATT&CK coverage map, and response validation summary
What Valty does not claim
Valty integrates and validates; it does not claim to own response execution by default.
Built for
SOC, CISO
Available through integrationsPublic / catalog-only

Endpoint Awareness

Connect endpoint posture and human-risk to the evidence behind your board and audit claims. Valty ships a built-in security-awareness training module — assign it, track completion, and feed it alongside your endpoint signals into the same evidence model — so training completion and device compliance become sourced, fresh controls that stand behind a board claim rather than a separate spreadsheet.

Proof you can inspect
Security-awareness training completion evidence, endpoint posture card, human-risk summary, and device compliance state
What Valty does not claim
Valty uses endpoint data as evidence through your existing tools; the built-in training module is native, but Valty does not replace your endpoint protection platform.
Built for
IT, security awareness, CISO
Available through integrationsPublic / catalog-only

Zero Trust Assurance

Verify zero-trust posture across the systems you already own, then price the gaps. Valty reads identity, device, network, data, cloud, API, and workload evidence, maps each signal to the control it satisfies across the zero-trust pillars, and shows where coverage is current, stale, or missing — so a zero-trust posture claim becomes per-pillar evidence with a dollar consequence attached, not an assertion.

Proof you can inspect
Per-pillar readiness matrix, cross-control proof card, evidence-freshness state, and the exposure attached to each gap
What Valty does not claim
Valty verifies zero-trust evidence; it does not replace your ZTNA, SASE, NAC, or identity platform.
Built for
CISO, identity lead
Roadmap previewPublic / catalog-only

API Security

Turn API inventory, contracts, and auth posture into risk evidence your security and platform teams can act on.

Proof you can inspect
Design-partner API contract and auth posture evidence pack
What Valty does not claim
Dedicated API-security workflows are not marketed as live until design-partner evidence is validated.
Built for
AppSec, platform engineering
Roadmap previewPublic / catalog-only

Software Assurance / QA

Give engineering and security leaders release evidence they can inspect instead of relying on status claims.

Proof you can inspect
Design-partner release evidence and quality proof pack
What Valty does not claim
Dedicated QA workflows stay in roadmap/design-partner status until customer evidence supports broader claims.
Built for
Engineering, QA, product