Public artifacts stay sanitized
Marketing pages use approved screenshots, demo iframes, and factual trust copy rather than private tenant data.
Security
A stage-honest trust surface: data access, tenant isolation, encryption, access control, audit logging, subprocessors, incident response, and compliance roadmap. The detailed security package is available under NDA.
Request security documentationOne engine, one set of evidence. Valty quantifies through FAIR, roots its V-Probe attestation in a TPM-held key, and maps that evidence across 30+ frameworks, 2,700+ controls carrying verbatim regulatory text, including SOC 2, ISO 27001:2022, NIST CSF 2.0, PCI DSS 4.0.1, HIPAA, GDPR, CMMC / NIST 800-171, FedRAMP and CIS v8, then translates into what DORA, SEC cyber-materiality and the EU AI Act ask for.
Marketing pages use approved screenshots, demo iframes, and factual trust copy rather than private tenant data.
Every security statement should be either public, gated, roadmap, or blocked until reviewed evidence exists.
Docs, proof packs, and trust artifacts route through access controls when the material is workspace-bound.
Security copy should update when source coverage, subprocessors, or control boundaries change.
Trust proof component
Security, federal, and trust-center pages need evidence confidence more than animation. This insert uses attestation tier and framework mode rather than decorative commercial blocks.
EvidenceTrustCard + EvidenceShield
FrameworkModeStack
Valty works from read-only access to the evidence sources you already operate: a scanner export, a GRC control export, a cloud posture signal. No new agent, no privileged shell, no write access to your production environment.
Each customer’s evidence is isolated to its own workspace. There is no cross-tenant evidence exposure and no shared inference across accounts. Your proof objects never train or inform another tenant.
Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Source systems remain your system of record; Valty stores normalized proof objects, not a copy of your control plane.
Workspace access is role-scoped and protected with SSO and multi-factor authentication. Administrative actions are least-privilege and logged.
Claim review and publication state are recorded: who reviewed a claim, the exact claim text, the evidence behind it, and the publication decision, so a board or auditor can trace any figure to its source.
Our subprocessor list is published in full on this page (no NDA needed to read it). Data-residency specifics, retention terms, and the full DPA are available on request under NDA as part of design-partner onboarding. Email security@valty.ai for the current security package.
We maintain a defined security-incident process with customer notification commitments. Disclosure and questions route to security@valty.ai (PGP key available).
We are early stage and say so: SOC 2 Type II is on the roadmap, not yet complete. We map to SOC 2, ISO 27001, and NIST CSF today and will publish audited attestations as they are earned. No implied certification we have not yet achieved.
Public trust artifacts
These are published in full, not gated. The full DPA, security questionnaire, and current subprocessor attestations are available under NDA via the design-partner path.
Subprocessors
Valty stores normalized, tenant-isolated proof objects, not your source-of-truth security systems. The processors below support that. Data residency, retention, and the full DPA are available on request.
| Subprocessor | Role | Region |
|---|---|---|
| Vercel | Application hosting and CDN | USA + global edge |
| Neon | Managed PostgreSQL database for tenant-isolated proof objects and account data | USA |
| Upstash | Redis for rate limiting and queueing | USA |
| Google Cloud Platform | Secret Manager and supporting infrastructure services | USA |
| Stripe | Payment processing for billing and subscriptions | Global |
| OAuth sign-in for product workspace login | Global | |
| Resend | Transactional email for service and notification messages | USA |
| Attio | CRM for sales and marketing contacts | USA |
| Apollo.io | Website-visitor enrichment, consent-gated | USA |
| Telegram | Operational lead and telemetry notifications to the founding team, consent-gated | Global |
Data retention
Indicative retention windows. Customer-specific schedules are set in the DPA; data is deleted or returned on request at offboarding.
| Data class | Default retention | Notes |
|---|---|---|
| Proof objects (normalized evidence) | Life of engagement | Tenant-isolated; deleted/returned at offboarding |
| Lead / contact data | Until you opt out | Held in Attio CRM; deletion on request |
| Application & access logs | 90 days | Security and audit; then rotated |
| Backups | ≤ 35 days | Encrypted; rolling window |
| Source-of-truth security data | Not retained | Stays in your systems; Valty reads, does not copy |
Control boundary
| Area | Valty | Customer |
|---|---|---|
| Source-of-truth (scanners, GRC, cloud, identity) | Reads (read-only) | Owns & operates |
| Evidence normalization & proof objects | Owns | Reviews |
| Financial-risk model & assumptions | Owns (visible/challengeable) | Challenges & approves |
| Publication decision (what leaves the room) | Gates / flags | Final sign-off |
| Enforcement / remediation execution | Recommends & ranks | Executes |
Procurement & security review
Vendor security questionnaires, NDA, and the full DPA are handled through the design-partner path. Request the package or email security@valty.ai for posture questions before the engagement is scoped.