Public artifacts stay sanitized
Marketing pages use approved screenshots, demo iframes, and factual trust copy rather than private tenant data.
Security
This page is a trust-center spine: data boundary, tenant isolation, encryption/key management, audit logs, subprocessors, disclosure channel, and public status.
Review proof workflowMarketing pages use approved screenshots, demo iframes, and factual trust copy rather than private tenant data.
Every security statement should be either public, gated, roadmap, or blocked until reviewed evidence exists.
Docs, proof packs, and trust artifacts route through access controls when the material is workspace-bound.
Security copy should update when source coverage, subprocessors, or control boundaries change.
Trust proof component
Security, federal, and trust-center pages need evidence confidence more than animation. This insert uses attestation tier and framework mode rather than decorative commercial blocks.
EvidenceTrustCard + EvidenceShield
FrameworkModeStack
Public pages use sanitized product artifacts and do not expose private source-adapter behavior, tenant data, or customer-specific claims.
Marketing copy should state product boundaries factually and link to audited product evidence when available.
Security language remains factual until a reviewed trust-center artifact is published.
Claim-review sign-off artifacts record reviewer, date, exact claim text, evidence, publication state, and re-review date.
List only reviewed subprocessors and publication status in the trust-center surface.
Route security inquiries to security@valty.ai and keep response claims factual.