Control begins with the control plane itself.
Valkyrie is in active development. This page states plainly what is in progress and what is planned — it will never claim certifications, audits or guarantees that don't exist yet.
Principles
The standard we hold ourselves to.
- The control plane must satisfy the same standard of governance it enforces for others.
- Least necessary data: we design against indiscriminate retention of sensitive payloads.
- Every administrative action should be attributable and reviewable.
- Honesty over marketing: we state what is implemented, in progress and planned.
Status
Where each area stands.
Statuses below are updated as the platform matures. Nothing on this page is a certification claim.
Tenant isolation
In progressIsolation boundaries between customer organizations are part of the core architecture and are being validated against real enterprise requirements.
Encryption
In progressEncryption in transit and at rest for customer data, with provider credentials held in isolated storage.
Credential and secrets handling
In progressProvider credentials are isolated from application code paths and never exposed to client-side surfaces.
Access control
In progressRole-based access within organizations, scoped API keys for programmatic access.
Administrative logging
PlannedAn attributable log of administrative actions across the control plane.
Data retention
PlannedConfigurable retention windows for traces and evidence, with defaults that favor minimal retention.
Customer payload handling
In progressEvidence records are designed to capture decisions and metadata without requiring indiscriminate retention of request payloads.
Backups and recovery
PlannedDefined backup and recovery objectives for control-plane state and evidence records.
Vulnerability reporting
In progressA documented intake for security researchers and customers to report vulnerabilities, with acknowledgment timelines.
Incident response
PlannedA documented incident-response process covering detection, customer notification and post-incident review.
Subprocessors
PlannedA published list of subprocessors and the role each plays, maintained as the platform's dependencies are finalized.
Contact
Report a vulnerability or ask a question.
Security questions and vulnerability reports go directly to the founding team at security@valkyrieplatform.com. We acknowledge reports and keep reporters informed through resolution.
Review the architecture with your security team.
Have requirements to examine? We'll walk through the architecture and these controls with your security team.