Last updated: June 29, 2026
Built like you'll audit it.
Every architectural decision starts from the assumption that a serious procurement team will read the diagram. We don't hand-wave isolation, we don't lock you into a single AI vendor, and we never log the literal contents of your database.
Below is exactly what we do today, what's on the compliance roadmap, and how to reach a human when you have a sharper question.
Six commitments we hold ourselves to on every release.
Data isolation by design
InsightralTM deploys into your data center or private cloud. Customer data never crosses a Valora-hosted SaaS boundary — you operate the full stack in your perimeter.
Encryption at rest and in transit
TLS 1.2+ on every external connection. AES-256 encryption at rest on managed storage. KMS-managed keys with documented rotation. No customer secrets ever land in repos, logs, or error reports.
Fingerprint-only egress (InsightralTM)
When InsightralTM reports a finding, only the metadata required for monitoring crosses your network boundary — aggregate evidence, not sensitive query content or customer identifiers. Labels you assign stay in your environment.
Multi-provider AI — no single-LLM lock-in
InsightralTM routes optional AI summaries through your preferred provider inside your private cloud. We never use your data to train a model, and inference stays in the deployment you control.
Distroless, non-root, SHA-pinned images
Every component we ship is built for production hardening — minimal attack surface, verified at deploy time, and operated entirely in your private cloud.
Audit logs on every state change
Every incident, alert dispatch, subscription change, and support impersonation is recorded through an outbox pattern with an immutable trail. Logs are tenant-scoped — support can act on your data only via impersonation, and every action is attributable.
Where we are today — and what we're honest about not having yet.
SOC 2 Type II
In progressNot yet certified. Audit window opens 2026, targeting report delivery Q4 2026. Type I is targeted as an interim milestone; current controls documentation is available under NDA.
GDPR
DPA on requestStandard Data Processing Addendum available. InsightralTM deploys in your perimeter — data residency follows your infrastructure choices.
CCPA
CompliantCalifornia consumer rights honored. Subject access requests handled via privacy@valorasolutionsinc.com within 30 days.
HIPAA
RoadmapNo BAA available today. Not appropriate for PHI workloads in current generation. BAA targeted alongside SOC 2 Type II.
What we collect, what we never touch, and how long we keep it.
What we collect
- Aggregate metrics and findings. Counters from
pg_stat_*,performance_schema,$currentOp,sys.dm_*. Numbers, not literals. - SHA-256 fingerprints of database identifiers — host + schema + symbol. Used to correlate findings without revealing what they map to.
- Account and billing data needed to provision the service: email, organization name, Stripe subscription state.
- Deployment telemetry — version, uptime, crash reports — only with explicit opt-in.
What we never collect
- Literal values from rows inside your database. Not in logs, not in findings, not in support tickets.
- Query bodies with parameter values, EXPLAIN plans with actual literals, or any payload that round-trips customer PII.
- LLM prompts or completions when you bring your own key — the dashboard proxies the call without persisting the content.
- Anything we can't justify with a specific product reason. If we don't need it for the feature, we don't store it.
Retention windows
- Findings and aggregate metrics: retention windows follow your deployment configuration — typically 30 / 90 / 365 days on paid tiers at GA.
- Audit logs: 12 months minimum; 7 years on Scale.
- Account closure: tenant data and assets purged within 30 days of cancellation, except where law requires longer retention.
Your perimeter is the boundary. Always.
InsightralTM runs entirely in your data center or private cloud. There is no Valora-hosted multi-tenant control plane — you operate the collector, dashboard, and optional AI router inside your network.
- Agent-only database access. Connection strings stay on the collector host. The dashboard never receives raw credentials from your agents.
- Fingerprint-only egress. Findings carry aggregate evidence — not sensitive query content or bind parameters.
- Connect your preferred AI provider in your private cloud. Optional explanations call your provider key from inside your deployment. Valora does not operate shared inference for customer workloads.
- Distroless, cosign-signed images. Collector and dashboard ship as verifiable containers you can scan and pin in your registry.
- Never auto-remediate on customer infrastructure. This is a permanent product commitment — we observe and advise, we don't mutate.
Found something? Tell us — we'll act fast and credit you.
Email sales@valorasolutionsinc.com with reproduction steps and the affected version. We acknowledge within 24 hours, ship a fix or mitigation as fast as the severity warrants, and request a 90-day coordinated disclosure window before any public write-up.
- Safe-harbor. Good-faith research against your own deployment or our public sandbox will not be the basis for legal action.
- Credit. With your permission, we acknowledge reporters in the release notes for the fix.
- Out of scope. Denial-of-service, social engineering of employees, and attacks against third-party providers we depend on.
Got a security question? Talk to our security team.
Security and compliance questions are not routed through a sales funnel. Write to us directly — a member of the security team will reply, usually the same business day, with a real answer instead of a portal link.
