One operating layer across AI applications, models and enterprise controls.
Valkyrie sits in the execution path between enterprise applications and model providers, applying versioned controls and recording the resulting evidence.
Architecture
Three planes, one system.
Governance is defined in the control plane, enforced in the runtime plane, and proven in the evidence plane. Each plane is inspectable on its own; together they form the operating layer.
01Control plane
Where governance is defined
- Organizations
- Applications
- Environments
- Policies
- Approvals
- Evaluations
02Runtime plane
Where every request is enforced
- Authentication
- Routing
- Enforcement
- Redaction
- Provider execution
03Evidence plane
Where outcomes become reviewable
- Traces
- Decisions
- Exceptions
- Incidents
- Exports
Request lifecycle
What happens to every request.
01
Authenticate
Every request is tied to a registered application, environment and credential.
02
Evaluate
The active policy version is loaded and evaluated against the request.
03
Act
The request is allowed, transformed, redacted, denied or held for human review.
04
Route
Approved traffic is routed to an allowlisted provider with isolated credentials.
05
Record
The decision, policy version and outcome are committed to the evidence plane.
Registry
Applications and environments, accounted for.
Every application is registered with an owner, an environment and a permitted use case. The registry is the inventory security teams ask for and the source of truth the runtime enforces against — development, staging and production are distinct, with controls that can differ by environment.
Governed Gateway
A stable integration surface across approved models and providers.
Applications integrate once. Behind the gateway, model allowlists, provider routing, rate and spend limits, and credential isolation are operated centrally — so changing a provider is an operational decision, not an application rewrite.
Policy & Guardrails
Versioned controls enforced on every request.
Policies are authored, versioned and approved in the control plane, then evaluated in the execution path: data-handling rules, tool and action permissions, redaction and denial, and human-review gates. The policy version that acted is recorded with every decision.
Exceptions
Consequential states stay under human authority.
Some requests should not resolve automatically. Review gates hold them for a decision, exceptions are tracked with an owner and an expiry rather than becoming permanent silent bypasses, and incidents link back to the traces that triggered them.
Evidence & Observability
A synchronized record of requests, policies and outcomes.
Decision timelines, trace inspection, exceptions and incidents, and evidence export live in one system that observes the same execution path it records — designed to avoid indiscriminate retention of sensitive payloads.
Evaluations & Release Controls
Test applications and policies before production.
Evaluation suites and regression tests run against applications and policy changes before they promote. Approval gates and environment promotion make the path from development to production explicit — and repeatable.
Integration
API-first by construction.
The platform is built API-first: the same interfaces that serve the product are the integration surface for your infrastructure, CI pipelines and internal tooling. An OpenAPI-documented public API is part of the core architecture, not an afterthought.
Deployment
A deployment model shaped by real enterprise requirements.
Valkyrie is in active development. Deployment topology, isolation guarantees and data-handling boundaries are being defined and validated against real enterprise requirements — we publish what is implemented, in progress and planned rather than claiming availability ahead of reality.
Walk the architecture with us.
Join the waitlist to follow the build and get access as it opens.