Skip to content

Security

What Valty accesses, how it’s protected, and what we can share.

A stage-honest trust surface: data access, tenant isolation, encryption, access control, audit logging, subprocessors, incident response, and compliance roadmap. The detailed security package is available under NDA.

Request security documentation
\ Compliance \

FAIR-native. Framework-aligned. Mandate-ready.

One engine, one set of evidence. Valty quantifies through FAIR, roots its V-Probe attestation in a TPM-held key, and maps that evidence across 30+ frameworks, 2,700+ controls carrying verbatim regulatory text, including SOC 2, ISO 27001:2022, NIST CSF 2.0, PCI DSS 4.0.1, HIPAA, GDPR, CMMC / NIST 800-171, FedRAMP and CIS v8, then translates into what DORA, SEC cyber-materiality and the EU AI Act ask for.

FAIR
Native engine
TPM 2.0
V-Probe rooted
SOC 2
Type II · mapped
ISO 27001
ISMS · mapped
NIST CSF
v2.0 · mapped
CMMC 2.0
DoD · translated
Mandates translated
DORA
EU · financial resilience
SEC 10-K
US · Item 1C materiality
EU AI Act
AI risk & governance
Boundary

Public website

Public artifacts stay sanitized

Marketing pages use approved screenshots, demo iframes, and factual trust copy rather than private tenant data.

Controls

Claim register

Security claims carry publication state

Every security statement should be either public, gated, roadmap, or blocked until reviewed evidence exists.

Access

Login-bound docs

Buyer proof is scoped by request

Docs, proof packs, and trust artifacts route through access controls when the material is workspace-bound.

Review

Quarterly or product-triggered

Trust pages get re-reviewed on product change

Security copy should update when source coverage, subprocessors, or control boundaries change.

Trust proof component

Trust claims show collection mode and evidence tier.

Security, federal, and trust-center pages need evidence confidence more than animation. This insert uses attestation tier and framework mode rather than decorative commercial blocks.

EvidenceTrustCard + EvidenceShield

Evidence trust

T1Hardware-attestedPassFresh 18h
T2Software-attestedPassFresh 2d
T3API-verifiedReviewFresh 4d
Hash-chain verified across the export window.

FrameworkModeStack

Evidence-mode coverage

Automated
62
Assisted
24
Manual
14

Data access

Valty works from read-only access to the evidence sources you already operate: a scanner export, a GRC control export, a cloud posture signal. No new agent, no privileged shell, no write access to your production environment.

Tenant isolation

Each customer’s evidence is isolated to its own workspace. There is no cross-tenant evidence exposure and no shared inference across accounts. Your proof objects never train or inform another tenant.

Encryption

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Source systems remain your system of record; Valty stores normalized proof objects, not a copy of your control plane.

Access control

Workspace access is role-scoped and protected with SSO and multi-factor authentication. Administrative actions are least-privilege and logged.

Audit logging

Claim review and publication state are recorded: who reviewed a claim, the exact claim text, the evidence behind it, and the publication decision, so a board or auditor can trace any figure to its source.

Subprocessors

Our subprocessor list is published in full on this page (no NDA needed to read it). Data-residency specifics, retention terms, and the full DPA are available on request under NDA as part of design-partner onboarding. Email security@valty.ai for the current security package.

Incident response

We maintain a defined security-incident process with customer notification commitments. Disclosure and questions route to security@valty.ai (PGP key available).

Compliance roadmap

We are early stage and say so: SOC 2 Type II is on the roadmap, not yet complete. We map to SOC 2, ISO 27001, and NIST CSF today and will publish audited attestations as they are earned. No implied certification we have not yet achieved.

Public trust artifacts

Read the policies, not just the claims.

These are published in full, not gated. The full DPA, security questionnaire, and current subprocessor attestations are available under NDA via the design-partner path.

Subprocessors

Every third party that touches the platform.

Valty stores normalized, tenant-isolated proof objects, not your source-of-truth security systems. The processors below support that. Data residency, retention, and the full DPA are available on request.

SubprocessorRoleRegion
VercelApplication hosting and CDNUSA + global edge
NeonManaged PostgreSQL database for tenant-isolated proof objects and account dataUSA
UpstashRedis for rate limiting and queueingUSA
Google Cloud PlatformSecret Manager and supporting infrastructure servicesUSA
StripePayment processing for billing and subscriptionsGlobal
GoogleOAuth sign-in for product workspace loginGlobal
ResendTransactional email for service and notification messagesUSA
AttioCRM for sales and marketing contactsUSA
Apollo.ioWebsite-visitor enrichment, consent-gatedUSA
TelegramOperational lead and telemetry notifications to the founding team, consent-gatedGlobal

Data retention

How long each data class is kept.

Indicative retention windows. Customer-specific schedules are set in the DPA; data is deleted or returned on request at offboarding.

Data classDefault retentionNotes
Proof objects (normalized evidence)Life of engagementTenant-isolated; deleted/returned at offboarding
Lead / contact dataUntil you opt outHeld in Attio CRM; deletion on request
Application & access logs90 daysSecurity and audit; then rotated
Backups≤ 35 daysEncrypted; rolling window
Source-of-truth security dataNot retainedStays in your systems; Valty reads, does not copy

Control boundary

What Valty owns vs. what stays yours.

AreaValtyCustomer
Source-of-truth (scanners, GRC, cloud, identity)Reads (read-only)Owns & operates
Evidence normalization & proof objectsOwnsReviews
Financial-risk model & assumptionsOwns (visible/challengeable)Challenges & approves
Publication decision (what leaves the room)Gates / flagsFinal sign-off
Enforcement / remediation executionRecommends & ranksExecutes

Procurement & security review

Need the full security package, DPA, or attestations?

Vendor security questionnaires, NDA, and the full DPA are handled through the design-partner path. Request the package or email security@valty.ai for posture questions before the engagement is scoped.

Request security documentation