Skip to content

Pricing

Pricing follows proof.

We are in a design-partner stage. Before a number is set, the operating motion needs to match. Start with free tools, no commitment required, or apply to the design-partner program.

Apply as a design partner
FreeTools, no commitment

Three per-seat tools are available without a sales call or a contract. Start from available evidence.

PartnerDesign partner, current stage

A structured engagement: co-designed around your operating motion, scoped deliverables, direct product influence.

ContactPortfolio & Enterprise, custom

Multi-company rollups, portfolio command, and enterprise procurement are scoped individually. No public list price.

Base platform + risk reduction modules

Start with the cyber-risk match. Turn on modules to move the number.

Valty Base gives a PE operating team the dollarized cyber-risk view: EBITDA-at-risk, evidence ledger, and proof pack. Each module is an optional control plane that models how much EBITDA-at-risk it can remove, then shows the evidence required to prove that reduction.

Required base

Security EBITDA match

Portfolio exposure, FAIR-style assumptions, board-ready proof, and confidence state. This is the shared risk currency every module attaches to.

EBITDA-at-riskEvidence freshnessProof packModule ROI

Dollar movements are illustrative decision-support examples. Actual before/after ranges depend on source coverage, portfolio context, remediation scope, and proof confidence.

Packaging by motion

Three entry motions. Module packs expand the account only after proof shows the risk move.

We do not publish a list price at this stage. The design-partner program is where pricing gets built alongside proof, so the commercial structure reflects the real operating workflow, not a standard seat model. What we can tell you is how a number gets scoped and how fast: base access first, module packs next, verified remediation only when the proof contract is clear.

What drives the number

  • Company count (single company vs. portfolio rollup)
  • Evidence source coverage (how many scanners / GRC / cloud / identity feeds)
  • Proof cadence (one-time artifact vs. continuous freshness)
  • Defense programs: a CMMC compliance pack is available while Phase II is suspended for review and Phase I remains, scoped through the design-partner intake. See the CMMC readiness path

Engagement shape

  • Free tools: no contract, no sales call, real artifact returned
  • Design-partner pilot: scoped engagement, founder pricing, direct product influence
  • Portfolio / Enterprise: multi-company, custom, procurement & security review

Procurement timeline

  • Free tools: minutes, self-serve
  • Design-partner pilot: typically days once scope and access are agreed
  • Enterprise: NDA + vendor security review, then a scoped statement of work

Available now

Free tools

Three no-commitment tools that return a real artifact, not a demo form. No contract. No sales call required.

What is included

  • EBITDA exposure calculator: estimate cyber-driven EBITDA impact from your own inputs
  • V-Probe evidence wedge: verify a control or finding with source coverage and confidence score
  • Guided demo request: structured walkthrough scoped to your buyer motion

What stays gated or custom

  • Workspace evidence connectors
  • Proof packs and board-ready export
  • Portfolio command and multi-company rollup
  • Action queue and hold-period tracking

Current stage

Design partner

We are in a design-partner stage. Pricing follows proof. The engagement is structured around your operating motion before a commercial number is set.

What is included

  • Full platform access for your team and source systems
  • Co-designed onboarding scoped to your evidence sources (scanners, GRC, cloud, identity, financial)
  • Direct product influence: open roadmap access, weekly review, and priority on the issues that block your proof motion
  • Proof pack and board narrative, reviewed for claim discipline before delivery
  • Joint accountability on evidence freshness and publication state

What stays gated or custom

  • Portfolio-wide rollup (requires Portfolio / Enterprise scope)
  • Automated procurement or SOC 2 audit pack delivery (roadmap)

Contact

Portfolio & Enterprise

Multi-company portfolio rollups, enterprise procurement, and supply-chain / federal engagements are scoped individually. No public pricing until the operating motion is matched.

What is included

  • Portfolio command: company-by-company exposure, action queue, and board rollup
  • Enterprise sourcing and procurement path (NDA, security review, vendor onboarding)
  • Federal / supply-chain readiness package and crosswalk assistance
  • Dedicated proof review and publication sign-off cadence

What stays gated or custom

  • Pricing is custom, dependent on company count, source coverage, and proof delivery cadence

Procurement and security review

Vendor security questionnaires, NDA, and procurement onboarding are handled through the design-partner path. Contact security@valty.ai for security posture questions before the engagement is scoped.

No fabricated customer references

We are early stage. Buyer references and public case studies are not available yet. The design-partner program produces real proof artifacts that design partners can use internally.

Source systems stay yours

Valty works alongside your scanners, GRC platforms, cloud consoles, identity systems, and financial models. Pricing reflects value added above those systems, not a renegotiation of your existing stack.

Estimates are decision-support, not warranties

Financial outputs (EBITDA estimates, risk quantifications, exposure ranges) carry method, confidence, and limitations. They are inputs for decisions, not contractual guarantees.

Common objections

Questions buyers ask before they engage.

These are the real questions a CISO, CFO, or PE operating partner asks about a cyber-risk platform that translates exposure into EBITDA impact. Answered directly, with the same claim discipline the product enforces.

Is the dollar number actually defensible?

Every financial output Valty produces carries four fields visible at the point of use: method, confidence band (P10 / base / P90), source coverage, and freshness date. The number is not decorative. It is a decision-support estimate built on a FAIR-aligned Monte Carlo model that shows its assumptions rather than burying them in a disclaimer.

What “defensible” means in practice: the EBITDA bridge shows which control gaps drive the exposure, what probability and magnitude assumptions underlie each scenario, and what the evidence coverage is for each assumption. A CFO or board reviewer can challenge any individual driver directly, rather than needing to accept or reject a headline figure on faith.

The model does not claim precision it cannot earn. Outputs are labeled decision-support estimates. When source coverage is thin, Valty labels the evidence gap and can block the claim from publication rather than silently publishing it. V1 does not automatically rewrite FAIR input ranges solely because source coverage is thin.

Method: FAIR-aligned Monte CarloConfidence: Displayed inline, P10–P90Freshness: Linked to source evidence refresh cadenceDesign partner
What do you need to install, and what access does this require?

Valty works from available evidence. It does not require a new scanner, agent install, or privileged shell access to your production environment. The typical starting point is read access to the evidence sources you already operate: a scanner export, a GRC control export, a cloud security posture signal, or an identity and findings feed.

The platform ingests, normalizes, and enriches what is already there, and sits above your systems as a translation layer. Getting started does not require replacing them. Source adapters are scoped by the customer; data flows into Valty on the terms you define, not ours.

In the design-partner stage, the integration is co-designed with your team. We map which evidence sources cover which control domains, agree on freshness thresholds and owner assignments, and scope the connector surface to exactly what the proof motion needs, and nothing more.

No new scanner requiredSource access: read-only, customer-scopedAugments your existing stack: no rip-and-replace to onboardDesign partner
How is this different from a GRC tool or a security rating?

Security ratings (BitSight, SecurityScorecard, etc.) score your external attack surface from the outside. They are fast and comparative, but they do not see your control verification state, your internal finding remediation status, or what the exposure means for EBITDA.

GRC platforms (ServiceNow, Archer, Tugboat Logic, etc.) track control frameworks, policy compliance, and audit workflows. They are the authoritative control register. What they rarely do is translate verified control gaps into a financial impact estimate a CFO or board can act on, or rank remediation priorities by ROI rather than framework weight.

Valty is a translation layer, not a competitor to either. It reads from your GRC and your scanner, maps control gaps to financial exposure scenarios using a FAIR-aligned model, ranks remediation by expected EBITDA impact per dollar spent, and packages the result as a board-ready proof artifact with source, confidence, and freshness visible. The GRC is still the control record. The rating is still the external signal. Valty is the business-impact layer above both.

Ratings: external signal only. Valty: verified internal control stateGRC: control record. Valty: financial translation + proof packagingIntegration: reads from both; no rip-and-replace to onboardDesign partner
Do you store our security data, and who owns it?

Your source-of-truth systems stay yours. Valty does not become the record system for your controls, findings, cloud posture, identity state, or financial model. Those remain in the systems you already operate.

Valty normalizes evidence from those systems into a proof object, a structured artifact that links the claim, the source, the confidence, the freshness, and the publication state. That proof object is tenant-isolated within your Valty workspace. No cross-tenant evidence exposure. No shared inference across accounts.

Data residency, retention periods, and subprocessor scope are addressed in the vendor security questionnaire and NDA, which are part of every design-partner onboarding. We do not publish detailed subprocessor lists without a reviewed trust-center artifact behind them. Contact security@valty.ai for the current security posture package.

Customer owns source systemsProof objects: tenant-isolated in your workspaceSecurity posture: available under NDA or design-partner onboardingDesign partner
You do not publish customer logos or references. Why should we trust this?

Valty has an active confidential design partnership, but does not publish the partner's identity or engagement specifics. We do not turn confidentiality into implied payment status, customer-authorized production scope, source authorization, or customer outcomes.

The current proof ladder is explicit. Valty-on-Valty dogfooding is real internal production evidence for the control, evidence, and governance workflows. The active design partnership adds external validation. The authenticated seeded demonstration shows the product path safely, but is not production or customer-outcome proof.

What buyers can evaluate directly is the deployed product, published methodology, inspectable proof model, and stage-labeled scenario library. Paid/customer outcomes, portability, and willingness to pay require separate evidence and are not represented here.

Stage-honest positioning is a constraint we enforce technically: the product’s claim-gate blocks unsupported assertions from being published in proof packs. We apply the same discipline to our own marketing copy.

Internal production proof: Valty-on-Valty dogfoodExternal validation: active confidential design partnershipPaid/customer outcomes: not representedDesign partner

Next step

Start without a sales call or apply to the design-partner program.