Skip to content
Security

Control begins with the control plane itself.

Valkyrie is in active development. This page states plainly what is in progress and what is planned — it will never claim certifications, audits or guarantees that don't exist yet.

Principles

The standard we hold ourselves to.

  • The control plane must satisfy the same standard of governance it enforces for others.
  • Least necessary data: we design against indiscriminate retention of sensitive payloads.
  • Every administrative action should be attributable and reviewable.
  • Honesty over marketing: we state what is implemented, in progress and planned.

Status

Where each area stands.

Statuses below are updated as the platform matures. Nothing on this page is a certification claim.

Tenant isolation

In progress

Isolation boundaries between customer organizations are part of the core architecture and are being validated against real enterprise requirements.

Encryption

In progress

Encryption in transit and at rest for customer data, with provider credentials held in isolated storage.

Credential and secrets handling

In progress

Provider credentials are isolated from application code paths and never exposed to client-side surfaces.

Access control

In progress

Role-based access within organizations, scoped API keys for programmatic access.

Administrative logging

Planned

An attributable log of administrative actions across the control plane.

Data retention

Planned

Configurable retention windows for traces and evidence, with defaults that favor minimal retention.

Customer payload handling

In progress

Evidence records are designed to capture decisions and metadata without requiring indiscriminate retention of request payloads.

Backups and recovery

Planned

Defined backup and recovery objectives for control-plane state and evidence records.

Vulnerability reporting

In progress

A documented intake for security researchers and customers to report vulnerabilities, with acknowledgment timelines.

Incident response

Planned

A documented incident-response process covering detection, customer notification and post-incident review.

Subprocessors

Planned

A published list of subprocessors and the role each plays, maintained as the platform's dependencies are finalized.

Contact

Report a vulnerability or ask a question.

Security questions and vulnerability reports go directly to the founding team at security@valkyrieplatform.com. We acknowledge reports and keep reporters informed through resolution.

Review the architecture with your security team.

Have requirements to examine? We'll walk through the architecture and these controls with your security team.