Skip to content

Evidence verification wedge

Upload one evidence file. Get a graded proof object back.

A control export, a finding list, or a cloud posture report is enough to start. The V-Probe normalizes it into a confidence-graded evidence object, so you see what is supported, inferred, and blocked before any claim leaves the room.

3

Evidence inputs

Control catalog export, finding list, or cloud posture report. Any one is enough to start.

<4 hrs

Target time to first signal

Target turnaround. Valty maps provided artifacts to the control catalog and returns a confidence-graded evidence object.

Evidence object

Output artifact

A control-verification proof card with source, confidence, freshness, and gap ledger.

No commitment required

What you can provide without a sales call

  • A control catalog or compliance export (CSV, XLSX, PDF, any format)
  • A finding list from a recent vulnerability scan or pen test (sanitized is fine)
  • A cloud posture report, CIS benchmark output, or security score card
  • Owner and review-date metadata for any of the above, if available
  • The framework or compliance target you are trying to evidence (SOC 2, ISO 27001, CMMC, NIST CSF; part of 30+ framework catalogs, 2,700+ source-cited controls)

Evidence verification workflow

From source artifact to inspectable proof object.

The V-Probe is not a gap analysis report. It is an evidence normalization step that tells you, and an auditor, exactly what state each control is in before a claim is published.

Ingest

Artifact ingestion

Source artifact enters the evidence pipeline

Valty accepts control exports, finding lists, cloud posture reports, and benchmark outputs in any format. The probe normalizes them into source-linked evidence objects.

Map

Evidence normalization

Controls and findings get owner, freshness, and confidence

Each control is mapped to the relevant framework requirement. Missing coverage, stale evidence, and contested attestations surface in the gap ledger, not buried in a spreadsheet.

Verify

Coverage scoring

The verification wedge scores coverage and freshness

The V-Probe output grades each control by attestation tier (T1 hardware-attested → T4 manual), evidence freshness, and whether the claim is publishable or blocked.

Proof

Proof card output

Output is an inspectable evidence object, not a score

The proof card shows what is supported, what is inferred, what is blocked, and what an auditor or board reviewer would see if the export happened today.

Output preview

The evidence object you receive after a V-Probe run

The control catalog surface shows attestation tier, freshness, source, and publication state, alongside the gap ledger for stale or inferred evidence.

  • Attestation tier per control (T1 → T4)
  • Evidence freshness and review date
  • Publishable, gated, and blocked claim states
  • Gap ledger with owner and next action
  • Framework crosswalk (SOC 2, CMMC, ISO, NIST CSF)
Control Catalog product surface
Control CatalogEvidence objects with owner, source, freshness, and confidence, set before a finding becomes a claim.

Control evidence

Source
Operator-provided catalog or export
Confidence
Attestation-tier graded
Freshness
Source review date preserved

Finding coverage

Source
Provided vulnerability scan or pen-test output
Confidence
Mapped to control catalog
Freshness
Ingestion timestamp

Gap ledger

Source
Missing or stale coverage detected on probe run
Confidence
Factual, not inferred
Freshness
Current as of artifact date

Proof card output

Source
V-Probe normalized evidence object
Confidence
Publishable / gated / blocked labeled
Freshness
Requires re-probe on source change

Decision-support boundary

V-Probe output reflects the state of the evidence you provide.

The verification wedge grades coverage based on the artifacts you upload. It does not perform live scanning, penetration testing, or cloud discovery. Evidence quality is bounded by source quality. Stale inputs produce stale proof cards. The output is a starting position for a board or audit conversation, not a certification statement.

Next step

Run V-Probe, then connect source systems for live evidence.

The V-Probe works on any artifact you already have. When source connectors are live, freshness updates automatically and the gap ledger closes in real time.