Skip to content

Compliance

Compliance evidence with collection mode, freshness, and blocked-claim visibility, before the auditor asks.

Valty connects compliance programs to a structured evidence model. Controls are organized by framework, collection mode, freshness, and owner, so audit-ready proof is a workflow output, not a last-minute assembly.

3Evidence modes
30+Framework catalogs
NoneRip-and-replace to onboard

Operating questions

The three questions this page has to answer.

Board, operating, and proof questions arrive from different seats. The same evidence model has to answer all three without contradicting itself.

Board question

What frameworks are we compliant with, and what evidence supports each assertion?

Board-level compliance statements need framework coverage by evidence mode, gap count, and the remediation plan for blocked controls, not a summary with no audit trail.

Operating question

Which controls are stale, who owns refresh, and what blocks our next audit package?

Program operations depend on freshness tracking per control, owner action queues, and a proof-ready export path that reflects the current state of evidence, not the state at last quarter review.

Proof needed

What can we submit to the SOC 2 auditor, CMMC assessor, or ISO reviewer that is defensible?

Audit-grade submission requires collection mode, hash-chain integrity, freshness, and a blocked-claim ledger that separates what is supported from what is still in progress.

Evidence architecture

Three modes. Every control accounted for.

Collection method is visible alongside evidence so assessors can apply appropriate reliance, not assume all evidence was gathered the same way.

Source-verified

Automated

Source-verified evidence collected directly from scanner APIs, cloud providers, and identity systems with timestamp and hash integrity.

  • Cloud config scan results
  • Scanner finding sync
  • Identity provider signals

Agent-supported

Assisted

Agent-supported evidence where Valty prompts the owner, validates the response format, and tracks the attestation chain.

  • Policy review prompts
  • Owner acknowledgment workflows
  • Vendor attestation intake

Owner-attested

Manual

Owner-submitted attestation with date, reviewer, and re-attestation deadline, flagged for auditor review.

  • Physical control attestation
  • External assessor uploads
  • Exception documentation

Proof surface

Proof packs carry framework crosswalk, claim state, and blocked-claim ledger.

Every compliance export includes which claims are evidence-backed, which are inferred and should be reviewed, and which are blocked until a source refresh or owner re-attestation completes.

  • Framework crosswalk with control mapping and gap identification
  • Claim-state view: publishable, inferred, and blocked
  • Freshness ledger with per-control re-attestation deadlines
  • Export target review before board, auditor, or assessor delivery

Framework coverage estimates reflect available source connections. Evidence completeness depends on source-system access scope agreed at setup.

Prove product surface
ProveClaims leave the platform as proof cards, board packs, and exportable evidence packages.

Framework and source support

Works with the source systems and frameworks you already have.

Frameworks

  • SOC 2 (Type I and Type II evidence workflows)
  • ISO 27001:2022 (control and Annex A mapping)
  • NIST CSF 2.0 (function and subcategory evidence)
  • PCI DSS 4.0.1 (requirement and testing-procedure mapping)
  • HIPAA Security Rule (safeguard evidence)
  • CMMC Level 1 and Level 2 / NIST 800-171 (320 assessment objectives)
  • FedRAMP (OSCAL SSP, SAP, SAR, and POA&M generation)
  • GDPR, DORA, NIS2, and 20+ more source-cited catalogs
  • Custom framework and internal policy mapping

Source connections

  • Vulnerability scanners (normalized findings with freshness)
  • GRC platforms (control status and owner sync)
  • Cloud provider APIs (config and identity signals)
  • Identity providers (access control evidence)
  • Agent-assisted intake for policy and vendor responses

Proof matrix

Compliance claims and their proof requirements

The matrix reflects what Valty can produce, what requires owner action, and what stays blocked until evidence is current. Assessors can inspect the same view during audit delivery.

Framework coverage assertion

Source
Control catalog with mode and freshness per control
Confidence
Automated / assisted / manual, labeled
Freshness
Per-control collection timestamp

Automated evidence artifact

Source
Direct source API or scanner ingestion
Confidence
Source-verified, hash-chain tracked
Freshness
Collection timestamp; recollected on sync

Owner attestation record

Source
Assisted or manual attestation workflow
Confidence
Owner-attested; flagged for assessor review
Freshness
Re-attestation deadline set at intake

Gap identification

Source
Framework crosswalk vs. evidence catalog
Confidence
Evidence gap, not a risk opinion
Freshness
Recalculated on framework update or source change

Audit export package

Source
Proof pack with publishable claims only
Confidence
Evidence-backed; blocked claims excluded
Freshness
Freshness reviewed before assessor delivery

Blocked claim (stale evidence)

Source
Expired or un-refreshed source artifact
Confidence
Not publishable until refresh
Freshness
Owner action required; deadline flagged

Connect existing source systems. Get audit-ready proof on the next cycle.

Valty is built for compliance teams that already have scanners, GRC tools, and cloud access, and need evidence organized by framework, mode, and freshness before the next audit request arrives.

Valty is currently in design-partner and early-access stage. No fabricated customers, no hard pricing. Estimates labeled decision-support.