Inspect the hosting architecture, subprocessors, and assurance status before sharing company evidence. Security requirements and supporting documentation are scoped directly with your team.
Infrastructure. Marketing and application hosting run on Google Cloud Platform (Cloud Run) behind Google Cloud's global HTTPS load balancer, verified against production infrastructure on 2026-09-05. The application also uses a Neon Postgres database and Upstash Redis, with production secrets stored in GCP Secret Manager.
Tenant access. Workspaces use application role checks and PostgreSQL row-level security. Review the proposed workflow and its verification evidence during diligence.
Encryption. TLS 1.2 minimum; TLS 1.3 negotiated on modern clients (enforced at the edge). AES-256 at rest through provider-managed keys; these are provider controls, not a Valty certification.
Independent assurance. SOC 2 Type II and FedRAMP are not yet achieved. ISO 27001 is under evaluation, and no independent third-party penetration test is completed.
Separate services for marketing and the application
The marketing site and product run as separate Cloud Run services behind a shared Google Cloud HTTPS load balancer. Their data processing has different purposes, described in the subprocessor list below.
Access
Access-control architecture
Workspace scope in application and database controls
The application implements workspace and role checks alongside PostgreSQL row-level security. The scope and verification evidence for the proposed workflow are reviewed during security diligence.
Secrets
Secret management
Runtime credentials managed through Secret Manager
Production secrets are managed in GCP Secret Manager and supplied to the services as runtime configuration. Secret values are separate from the public website source.
Auth
Auth posture
Workspace authentication and session scope
The application implements Auth.js sessions with signed JWT cookies and Google sign-in when configured. Confirm sign-in options and administrator requirements for your engagement during security review.
Proof matrix
Certification and compliance posture: source, confidence, freshness
Every certification claim carries publication state, source, and freshness so buyers can assess what is audited versus what is a design intent.
ClaimSourceConfidenceFreshness
SOC 2 Type IISecurity assurance roadmapNot yet achieved. Audit readiness is planned; no completion date is committed.Request the current assurance scope during security review
FedRAMPLong-term federal compliance roadmapNot yet achieved. Future roadmap; no authorization is in progress.Status reviewed with federal engagement milestones
ISO 27001Under evaluationUnder evaluation. No active certification engagement.No assessment date committed
Penetration testNot yet completed by independent third partyInternal review only at this stageNo external assessment date committed
Data-processing documentsPrivacy policy and data-processing baselineBaseline in place; formal DPA available on requestRequest the current processing terms and subprocessor schedule
Encryption at restManaged storage and database encryption; Google Cloud and NeonProvider controls; not a Valty certificationReview the applicable provider documentation during diligence
Inside the application
A real interface with its limitations visible.
This capture shows the EBITDA view for the fictional Portco C. It demonstrates how the interface presents modeled loss, evidence coverage, and model validation; it does not report Valty's own finances or a customer result.
Valty EBITDA interface · illustrative dataReal Valty application captures with deterministic illustrative data. No customer data or customer outcomes. Captured 2026-08-31; this view shows Portco C in the Illustrative Portfolio.Open full-size product view ↗
What to look for
Input confidence does not replace model validation.
The selected company and illustrative portfolio remain visible
Modeled annual loss is distinguished from maintainable EBITDA
Evidence coverage and model validation have separate labels
Model validation is marked pending in this capture
Real Valty application captures with deterministic illustrative data. No customer data or customer outcomes. This product illustration uses different inputs from the sample decision memo.
Architectural proof
What is reviewable at design-partner stage without an NDA.
Multi-tenant isolation
Source
Workspace and role checks with PostgreSQL row-level security
Confidence
Review the proposed workflow and supporting verification evidence during diligence
Freshness
Reviewed whenever database access controls change
Credential storage
Source
GCP Secret Manager supplies runtime configuration to the hosted services
Confidence
Hosting and secret-management architecture; supporting material scoped during security review
Freshness
Ask about credential access and rotation for the proposed scope
Data residency
Source
Cloud Run in us-central1; supporting-provider regions are listed below
Confidence
Current US processing footprint; no contractually pinned residency commitment is implied
Freshness
Reviewed when tenant data-residency requirements are scoped
Authentication
Source
Auth.js JWT sessions; Google sign-in when configured
Confidence
Sign-in requirements and workspace access are reviewed for the engagement
Freshness
Auth posture reviewed on library update cycle and on security inquiry
Encryption in transit
Source
TLS 1.2 minimum; TLS 1.3 negotiated on modern clients (enforced at the edge). No HTTP in production.
Confidence
Google Cloud HTTPS ingress; provider transport controls are separate from Valty certification
Operational; completeness reviewed before SOC 2 audit scope is finalized
Freshness
Retention varies by log type and configuration; confirm the required records during review
Subprocessors
Third-party services that process Valty customer or lead data.
This list is current as of the trust-center publication date. Changes are made when a subprocessor is added, removed, or changes scope. Enterprise customers may request advance notice of material subprocessor changes via security@valty.ai.
SubprocessorRoleScopeRegionCertification
Google Cloud PlatformApplication hosting (Cloud Run), global HTTPS load balancing/ingress, and Secret Manager for runtime configurationProduct + siteUSA (us-central1)SOC 2, ISO 27001
NeonManaged PostgreSQL database for tenant-isolated proof objects and account dataProductUSASOC 2 Type II
UpstashRedis for rate limiting and queueingProduct + siteUSASOC 2
StripePayment processing for billing and subscriptionsProductGlobalPCI DSS Level 1, SOC 2
GoogleOAuth sign-in for product workspace loginProductGlobalISO 27001, SOC 2
ResendTransactional email for service and notification messagesProduct + siteUSASOC 2
AttioCRM for sales and marketing contactsMarketingUSASOC 2
TelegramOperational lead and first-party telemetry notifications to the founding team (not consent-gated)MarketingGlobal—
Hosting and compute were verified on September 5, 2026. Other provider details reflect the most recent review. Provider certifications are separate from Valty's own assurance status; Valty does not independently audit these providers.
Incident communication
Understand the response process.
Review the incident notification and response policy for communication responsibilities and reporting expectations. Contact security@valty.ai for engagement-specific questions.
Security contact
Report a vulnerability or request security documentation.
Security researchers, buyers, and design partners can reach the Valty security team at security@valty.ai. Include the affected service and the information you need to review. NDA and DPA requests route through the same address.
Vulnerability disclosure
Coordinate all vulnerability reports through security@valty.ai. Include reproduction steps, scope, and severity assessment. We do not operate a public bug-bounty program at this stage; all disclosures are handled directly.
PGP key
A PGP public key is available on request for encrypted disclosure. Contact security@valty.ai to receive the key fingerprint before sending sensitive material.
Data processing agreement
Customers requiring a formal DPA (GDPR / CCPA / enterprise procurement) should request the baseline via security@valty.ai. Confirm the applicable processing terms and subprocessor schedule before sharing company evidence.
Request documentation for procurement, diligence, or design-partner evaluation.
Security questionnaires, DPA, architecture diagrams, and design-partner NDA route through security@valty.ai. The proof page shows what a Valty proof artifact contains before you commit to an engagement.