Public artifacts stay sanitized
Public product views use sanitized screenshots, interactive examples, and factual trust disclosures. Private customer data stays inside its workspace.
Security
A stage-honest trust surface: data access, tenant isolation, encryption, access control, audit logging, subprocessors, incident response, and compliance roadmap. The detailed security package is available under NDA.
One engine, one set of evidence. Valty quantifies through FAIR and maps available evidence onto the frameworks that matter for the engagement, including SOC 2, ISO 27001:2022, NIST CSF 2.0, CMMC / NIST 800-171, and the questions DORA, SEC cyber-materiality, and the EU AI Act ask. Mapping is not certification.
Public product views use sanitized screenshots, interactive examples, and factual trust disclosures. Private customer data stays inside its workspace.
Every security statement is public, available on request, identified as roadmap, or withheld until reviewed evidence exists.
Docs, proof packs, and trust artifacts route through access controls when the material is workspace-bound.
Security disclosures are reviewed when source coverage, subprocessors, or control boundaries change.
Evidence trust
Security, federal, and trust-center views show attestation tier, collection mode, freshness, and publication state beside each claim.
Evidence integrity
Collection modes
Illustrative mix across 100 tracked controls.
Valty works from read-only access to the evidence sources you already operate: a scanner export, a GRC control export, a cloud posture signal. No new agent, no privileged shell, no write access to your production environment.
Each customer’s evidence is isolated to its own workspace. There is no cross-tenant evidence exposure and no shared inference across accounts. Your proof objects never train or inform another tenant.
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Source systems remain your system of record; Valty stores normalized proof objects, not a copy of your control plane.
Workspace access is role-scoped and protected with SSO and multi-factor authentication. Administrative actions are least-privilege and logged.
Claim review and publication state are recorded: who reviewed a claim, the exact claim text, the evidence behind it, and the publication decision, so a board or auditor can trace any figure to its source.
Our subprocessor list is published in full on this page (no NDA needed to read it). Data-residency specifics, retention terms, and the full DPA are available on request under NDA as part of design-partner onboarding.
We maintain a defined security-incident process with customer notification commitments. Disclosure and questions route to the security mailbox; PGP key available on request.
We are early stage and say so: SOC 2 Type II is on the roadmap, not yet complete. We map to SOC 2, ISO 27001, and NIST CSF today and will publish audited attestations as they are earned. No implied certification we have not yet achieved.
Security package and disclosure: security@valty.ai.
Public trust artifacts
These are published in full, not gated. The full DPA, security questionnaire, and current subprocessor attestations are available under NDA via the design-partner path.
Subprocessors
Valty stores normalized, tenant-isolated proof objects, not your source-of-truth security systems. The processors below support that. Data residency, retention, and the full DPA are available on request.
| Subprocessor | Role | Region |
|---|---|---|
| Google Cloud Platform | Application hosting (Cloud Run), global HTTPS load balancing/ingress, and Secret Manager for runtime configuration | USA (us-central1) |
| Neon | Managed PostgreSQL database for tenant-isolated proof objects and account data | USA |
| Upstash | Redis for rate limiting and queueing | USA |
| Stripe | Payment processing for billing and subscriptions | Global |
| OAuth sign-in for product workspace login | Global | |
| Resend | Transactional email for service and notification messages | USA |
| Attio | CRM for sales and marketing contacts | USA |
| Apollo.io | Optional visitor identification, consent-gated | USA |
| Telegram | Operational lead and first-party telemetry notifications to the founding team (not consent-gated) | Global |
Data retention
Indicative retention windows. Customer-specific schedules are set in the DPA; data is deleted or returned on request at offboarding.
| Data class | Default retention | Notes |
|---|---|---|
| Proof objects (normalized evidence) | Life of engagement | Tenant-isolated; deleted/returned at offboarding |
| Lead / contact data | Until you opt out | Held in Attio CRM; deletion on request |
| Application & access logs | 90 days | Security and audit; then rotated |
| Backups | ≤ 35 days | Encrypted; rolling window |
| Source-of-truth security data | Not retained | Stays in your systems; Valty reads, does not copy |
Control boundary
| Area | Valty | Customer |
|---|---|---|
| Source-of-truth (scanners, GRC, cloud, identity) | Reads (read-only) | Owns & operates |
| Evidence normalization & proof objects | Owns | Reviews |
| Financial-risk model & assumptions | Owns (visible/challengeable) | Challenges & approves |
| Publication decision (what leaves the room) | Gates / flags | Final sign-off |
| Enforcement / remediation execution | Recommends & ranks | Executes |
Procurement & security review
Vendor security questionnaires, NDA, and the full DPA are handled through the design-partner path. Request the package or write security@valty.ai for posture questions before the engagement is scoped.