Trust & Security

Last updated: June 29, 2026

Built like you'll audit it.

Every architectural decision starts from the assumption that a serious procurement team will read the diagram. We don't hand-wave isolation, we don't lock you into a single AI vendor, and we never log the literal contents of your database.

Below is exactly what we do today, what's on the compliance roadmap, and how to reach a human when you have a sharper question.

Security posture

Six commitments we hold ourselves to on every release.

  • Data isolation by design

    InsightralTM deploys into your data center or private cloud. Customer data never crosses a Valora-hosted SaaS boundary — you operate the full stack in your perimeter.

  • Encryption at rest and in transit

    TLS 1.2+ on every external connection. AES-256 encryption at rest on managed storage. KMS-managed keys with documented rotation. No customer secrets ever land in repos, logs, or error reports.

  • Fingerprint-only egress (InsightralTM)

    When InsightralTM reports a finding, only the metadata required for monitoring crosses your network boundary — aggregate evidence, not sensitive query content or customer identifiers. Labels you assign stay in your environment.

  • Multi-provider AI — no single-LLM lock-in

    InsightralTM routes optional AI summaries through your preferred provider inside your private cloud. We never use your data to train a model, and inference stays in the deployment you control.

  • Distroless, non-root, SHA-pinned images

    Every component we ship is built for production hardening — minimal attack surface, verified at deploy time, and operated entirely in your private cloud.

  • Audit logs on every state change

    Every incident, alert dispatch, subscription change, and support impersonation is recorded through an outbox pattern with an immutable trail. Logs are tenant-scoped — support can act on your data only via impersonation, and every action is attributable.

Compliance status

Where we are today — and what we're honest about not having yet.

  • SOC 2 Type II

    In progress

    Not yet certified. Audit window opens 2026, targeting report delivery Q4 2026. Type I is targeted as an interim milestone; current controls documentation is available under NDA.

  • GDPR

    DPA on request

    Standard Data Processing Addendum available. InsightralTM deploys in your perimeter — data residency follows your infrastructure choices.

  • CCPA

    Compliant

    California consumer rights honored. Subject access requests handled via privacy@valorasolutionsinc.com within 30 days.

  • HIPAA

    Roadmap

    No BAA available today. Not appropriate for PHI workloads in current generation. BAA targeted alongside SOC 2 Type II.

Data handling

What we collect, what we never touch, and how long we keep it.

What we collect

  • Aggregate metrics and findings. Counters from pg_stat_*, performance_schema, $currentOp, sys.dm_*. Numbers, not literals.
  • SHA-256 fingerprints of database identifiers — host + schema + symbol. Used to correlate findings without revealing what they map to.
  • Account and billing data needed to provision the service: email, organization name, Stripe subscription state.
  • Deployment telemetry — version, uptime, crash reports — only with explicit opt-in.

What we never collect

  • Literal values from rows inside your database. Not in logs, not in findings, not in support tickets.
  • Query bodies with parameter values, EXPLAIN plans with actual literals, or any payload that round-trips customer PII.
  • LLM prompts or completions when you bring your own key — the dashboard proxies the call without persisting the content.
  • Anything we can't justify with a specific product reason. If we don't need it for the feature, we don't store it.

Retention windows

  • Findings and aggregate metrics: retention windows follow your deployment configuration — typically 30 / 90 / 365 days on paid tiers at GA.
  • Audit logs: 12 months minimum; 7 years on Scale.
  • Account closure: tenant data and assets purged within 30 days of cancellation, except where law requires longer retention.
Deployment isolation — InsightralTM

Your perimeter is the boundary. Always.

InsightralTM runs entirely in your data center or private cloud. There is no Valora-hosted multi-tenant control plane — you operate the collector, dashboard, and optional AI router inside your network.

  • Agent-only database access. Connection strings stay on the collector host. The dashboard never receives raw credentials from your agents.
  • Fingerprint-only egress. Findings carry aggregate evidence — not sensitive query content or bind parameters.
  • Connect your preferred AI provider in your private cloud. Optional explanations call your provider key from inside your deployment. Valora does not operate shared inference for customer workloads.
  • Distroless, cosign-signed images. Collector and dashboard ship as verifiable containers you can scan and pin in your registry.
  • Never auto-remediate on customer infrastructure. This is a permanent product commitment — we observe and advise, we don't mutate.
Responsible disclosure

Found something? Tell us — we'll act fast and credit you.

Email sales@valorasolutionsinc.com with reproduction steps and the affected version. We acknowledge within 24 hours, ship a fix or mitigation as fast as the severity warrants, and request a 90-day coordinated disclosure window before any public write-up.

  • Safe-harbor. Good-faith research against your own deployment or our public sandbox will not be the basis for legal action.
  • Credit. With your permission, we acknowledge reporters in the release notes for the fix.
  • Out of scope. Denial-of-service, social engineering of employees, and attacks against third-party providers we depend on.

Got a security question? Talk to our security team.

Security and compliance questions are not routed through a sales funnel. Write to us directly — a member of the security team will reply, usually the same business day, with a real answer instead of a portal link.