Skip to content

Security

What Valty accesses, how it’s protected, and what we can share.

A stage-honest trust surface: data access, tenant isolation, encryption, access control, audit logging, subprocessors, incident response, and compliance roadmap. The detailed security package is available under NDA.

Compliance

FAIR-native. Framework-aligned. Mandate-ready.

One engine, one set of evidence. Valty quantifies through FAIR and maps available evidence onto the frameworks that matter for the engagement, including SOC 2, ISO 27001:2022, NIST CSF 2.0, CMMC / NIST 800-171, and the questions DORA, SEC cyber-materiality, and the EU AI Act ask. Mapping is not certification.

FAIR
Native engine
Evidence
Source-linked
SOC 2
Catalog · not attested
ISO 27001
ISMS · mapped
NIST CSF
v2.0 · mapped
CMMC L2
Readiness · not certified
Mandates translated
DORA
EU · financial resilience
SEC 10-K
US · Item 1C materiality
EU AI Act
AI risk & governance
Boundary

Public website

Public artifacts stay sanitized

Public product views use sanitized screenshots, interactive examples, and factual trust disclosures. Private customer data stays inside its workspace.

Controls

Claim register

Security claims carry publication state

Every security statement is public, available on request, identified as roadmap, or withheld until reviewed evidence exists.

Access

Login-bound docs

Buyer proof is scoped by request

Docs, proof packs, and trust artifacts route through access controls when the material is workspace-bound.

Review

Quarterly or product-triggered

Trust information follows product changes

Security disclosures are reviewed when source coverage, subprocessors, or control boundaries change.

Evidence trust

Trust claims show collection mode and evidence tier.

Security, federal, and trust-center views show attestation tier, collection mode, freshness, and publication state beside each claim.

Evidence integrity

Evidence trust

T1Hardware-attestedPassFresh 18h
T2Software-attestedPassFresh 2d
T3API-verifiedReviewFresh 4d
Hash-chain verified across the export window.

Collection modes

Evidence-mode coverage

Illustrative mix across 100 tracked controls.

Automated
62 / 100
Assisted
24 / 100
Manual
14 / 100

Data access

Valty works from read-only access to the evidence sources you already operate: a scanner export, a GRC control export, a cloud posture signal. No new agent, no privileged shell, no write access to your production environment.

Tenant isolation

Each customer’s evidence is isolated to its own workspace. There is no cross-tenant evidence exposure and no shared inference across accounts. Your proof objects never train or inform another tenant.

Encryption

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Source systems remain your system of record; Valty stores normalized proof objects, not a copy of your control plane.

Access control

Workspace access is role-scoped and protected with SSO and multi-factor authentication. Administrative actions are least-privilege and logged.

Audit logging

Claim review and publication state are recorded: who reviewed a claim, the exact claim text, the evidence behind it, and the publication decision, so a board or auditor can trace any figure to its source.

Subprocessors

Our subprocessor list is published in full on this page (no NDA needed to read it). Data-residency specifics, retention terms, and the full DPA are available on request under NDA as part of design-partner onboarding.

Incident response

We maintain a defined security-incident process with customer notification commitments. Disclosure and questions route to the security mailbox; PGP key available on request.

Compliance roadmap

We are early stage and say so: SOC 2 Type II is on the roadmap, not yet complete. We map to SOC 2, ISO 27001, and NIST CSF today and will publish audited attestations as they are earned. No implied certification we have not yet achieved.

Security package and disclosure: security@valty.ai.

Public trust artifacts

Read the policies, not just the claims.

These are published in full, not gated. The full DPA, security questionnaire, and current subprocessor attestations are available under NDA via the design-partner path.

Subprocessors

Every third party that touches the platform.

Valty stores normalized, tenant-isolated proof objects, not your source-of-truth security systems. The processors below support that. Data residency, retention, and the full DPA are available on request.

SubprocessorRoleRegion
Google Cloud PlatformApplication hosting (Cloud Run), global HTTPS load balancing/ingress, and Secret Manager for runtime configurationUSA (us-central1)
NeonManaged PostgreSQL database for tenant-isolated proof objects and account dataUSA
UpstashRedis for rate limiting and queueingUSA
StripePayment processing for billing and subscriptionsGlobal
GoogleOAuth sign-in for product workspace loginGlobal
ResendTransactional email for service and notification messagesUSA
AttioCRM for sales and marketing contactsUSA
Apollo.ioOptional visitor identification, consent-gatedUSA
TelegramOperational lead and first-party telemetry notifications to the founding team (not consent-gated)Global

Data retention

How long each data class is kept.

Indicative retention windows. Customer-specific schedules are set in the DPA; data is deleted or returned on request at offboarding.

Data classDefault retentionNotes
Proof objects (normalized evidence)Life of engagementTenant-isolated; deleted/returned at offboarding
Lead / contact dataUntil you opt outHeld in Attio CRM; deletion on request
Application & access logs90 daysSecurity and audit; then rotated
Backups≤ 35 daysEncrypted; rolling window
Source-of-truth security dataNot retainedStays in your systems; Valty reads, does not copy

Control boundary

What Valty owns vs. what stays yours.

AreaValtyCustomer
Source-of-truth (scanners, GRC, cloud, identity)Reads (read-only)Owns & operates
Evidence normalization & proof objectsOwnsReviews
Financial-risk model & assumptionsOwns (visible/challengeable)Challenges & approves
Publication decision (what leaves the room)Gates / flagsFinal sign-off
Enforcement / remediation executionRecommends & ranksExecutes

Procurement & security review

Need the full security package, DPA, or attestations?

Vendor security questionnaires, NDA, and the full DPA are handled through the design-partner path. Request the package or write security@valty.ai for posture questions before the engagement is scoped.

Request security documentation