Framework coverage assertion
- Source
- Control catalog with mode and freshness per control
- Confidence
- Automated / assisted / manual, labeled
- Freshness
- Per-control collection timestamp
Compliance
Valty connects compliance programs to a structured evidence model. Controls are organized by framework, collection mode, freshness, and owner, so audit-ready proof is a workflow output, not a last-minute assembly.
Automated, assisted, and manual, with collection method visible to assessors.
SOC 2, ISO 27001, CMMC L2, FedRAMP, PCI DSS, HIPAA, GDPR, DORA and more: 2,700+ source-cited controls.
Valty augments your existing GRC and scanner systems; getting started does not require replacing them.
Operating questions
Board, operating, and proof questions arrive from different seats. The same evidence model has to answer all three without contradicting itself.
Board question
Board-level compliance statements need framework coverage by evidence mode, gap count, and the remediation plan for blocked controls, not a summary with no audit trail.
Operating question
Program operations depend on freshness tracking per control, owner action queues, and a proof-ready export path that reflects the current state of evidence, not the state at last quarter review.
Proof needed
Audit-grade submission requires collection mode, hash-chain integrity, freshness, and a blocked-claim ledger that separates what is supported from what is still in progress.
Evidence architecture
Collection method is visible alongside evidence so assessors can apply appropriate reliance, not assume all evidence was gathered the same way.
Source-verified
Source-verified evidence collected directly from scanner APIs, cloud providers, and identity systems with timestamp and hash integrity.
Agent-supported
Agent-supported evidence where Valty prompts the owner, validates the response format, and tracks the attestation chain.
Owner-attested
Owner-submitted attestation with date, reviewer, and re-attestation deadline, flagged for auditor review.
Proof surface
Every compliance export includes which claims are evidence-backed, which are inferred and should be reviewed, and which are blocked until a source refresh or owner re-attestation completes.
Framework coverage estimates reflect available source connections. Evidence completeness depends on source-system access scope agreed at setup.

Framework and source support
Proof matrix
The matrix reflects what Valty can produce, what requires owner action, and what stays blocked until evidence is current. Assessors can inspect the same view during audit delivery.
Valty is built for compliance teams that already have scanners, GRC tools, and cloud access, and need evidence organized by framework, mode, and freshness before the next audit request arrives.
Valty is currently in design-partner and early-access stage. No fabricated customers, no hard pricing. Estimates labeled decision-support.