ValarIQ

Trust & Security

Control-plane trust is verified. We publish the rest honestly.

ValarIQ sits between autonomous systems and execution. Buyers should see what is demonstrable today — including Discover, Team RBAC and grounded Ops Chat — what is maturing, and what is not claimed. No certification theatre.

Registry last verified: 2026-09-20

9

Verified

Demonstrable in production today.

5

Ready to Connect

Real controls with known limits. Expanding with customers — not a one-click production flip.

2

In Progress

Work underway. Not claimed complete.

Verified control-plane trust

What customers can rely on today

Architecture, access, tenant isolation, signed evidence, Discover, Team RBAC, Ops Chat and honest capability claims. These are verified in production.

Architecture

Verified

ValarIQ operates as a control plane between autonomous systems and consequential execution. It does not execute payments or hold customer funds. Core authority and policy decisions fail closed when required inputs cannot be evaluated.

Limitation. Customer execution stacks remain outside ValarIQ boundary.

Authentication and authorisation

Verified

Session-based UI authentication, scoped Bearer API keys, server-side workspace roles and tenant controls operate in production. SSO/SAML and SCIM are not activated.

Limitation. SSO/SCIM inactive; owner login requires manual verification.

PostgreSQL and RLS

Verified

Production uses a managed relational database with tenant-scoped row-level security. Automated tenant-isolation regression tests have passed.

Limitation. Multi-region database resilience not implemented.

Evidence integrity

Verified

Decision evidence is cryptographically signed within implemented scope. Legacy envelope formats remain readable and are labelled when unbound.

Limitation. Not claimed absolutely immutable; independent timestamping Coming.

Context Assurance

Verified

The deterministic core verifies configured provenance, integrity, freshness, completeness and consistency requirements used in autonomous-action decisions.

Limitation. Context Assurance does not independently guarantee that source information is factually true. Real external evidence providers remain Foundation or Ready to connect.

AI asset discovery

Verified

Design partners can discover agent-like surfaces via signed manifests, SYNTHETIC fixtures, and credentialed HubSpot / Microsoft Graph scanners when env secret refs are configured. Promote creates Agent Identity; discovered assets are never auto-authorised.

Limitation. ERP/Sage and network scanners remain Ready to Connect. Catalogue targets are READY TO CONNECT until credentials and scanners are configured.

Ops Chat (Insights)

Verified

Read-only Insights chat answers estate questions from live workspace records (agents, Discover, approvals, policy mode, recent control pressure). Unknown prompts refuse rather than invent.

Limitation. Not an LLM assistant; no write actions or payment execution through chat.

Team roles and invitations

Verified

Workspace owners and admins can invite members, change roles (owner, admin, approver, viewer) and revoke access. Role checks are enforced server-side on sensitive APIs.

Limitation. SSO/SCIM not activated; first-party email/OTP remains the Live path.

Roadmap honesty

Verified

The capability registry is the public source of truth. LIVE, FOUNDATION, READY TO CONNECT and COMING reflect current production evidence.

Limitation. Staging-only modules must not appear Live on production without release.

Diligence evidence

Dated evidence, not new green badges.

Ask us for the private evidence pack. Public Trust stays honest about single-region posture, backup drills, and SSO activation readiness.

Backup / restore drill
2026-08-29
Encrypted off-device PostgreSQL + signing material backup with integrity checks. Automated schedule still PARTIAL.
RTO / RPO honesty
Single-region today
No contractual multi-region HA claim. Fail-closed money path if ValarIQ is unavailable. Formal RTO/RPO not approved.
SSO activation
Ready to Connect
OIDC foundation shipped; not Live until a design-partner IdP dry-run is recorded.
Request private SSO runbook →

Evidence over time

Historical truth stays fixed. Current reliance stays honest.

ValarIQ preserves what was known and authorised when an autonomous action was decided. That historical record is not rewritten. Separately, Evidence Lifecycle asks whether the same evidence still supports a claim today, and when authority or context has moved, surfaces re-verification rather than silent change.

Maturing with customers

Ready to Connect means real, with known limits.

These controls exist and operate. They are not a flip-switch to full enterprise depth, and they are not vapourware either.

Monitoring

Ready to Connect

Application, decision, worker, queue, containment and operational visibility exist.

Limitation. Independent external uptime monitoring and formal on-call coverage remain unverified unless activated.

Incident response

Ready to Connect

Incident workflows, containment, release records and operational procedures exist.

Limitation. Contractual SLA, RTO and RPO commitments are not approved.

SDLC and dependencies

Ready to Connect

Tests, typecheck, bounded lint gate, dependency audit, claims checking and secret scanning operate before release.

Limitation. Hosted CI, enforced branch protection and continuous independent audit remain unverified. Working-tree promotion was corrected in Batch 0 (commit 84f9c99, 2026-08-29).

Encryption

Ready to Connect

HTTPS operates in production. Sensitive backups are encrypted.

Limitation. Universal storage encryption, customer-managed keys, KMS or HSM not verified.

Retention

Ready to Connect

Retention fields and workspace practices exist.

Limitation. Legally approved and fully automated retention schedule not verified.

In Progress

  • Availability and HA

    In Progress

    Single-region hosted deployment.

    Do not claim multi-region, multi-replica HA or contractual uptime.

  • Certifications

    In Progress

    No ISO 27001, SOC 2 or other certification.

    Framework mappings are not certification.

Full posture register

Diligence view

Complete public controls with status, description and limitation. Private custody evidence is shared during technical diligence, not published here.

  • AI asset discovery

    Verified

    Design partners can discover agent-like surfaces via signed manifests, SYNTHETIC fixtures, and credentialed HubSpot / Microsoft Graph scanners when env secret refs are configured. Promote creates Agent Identity; discovered assets are never auto-authorised.

    Limitation. ERP/Sage and network scanners remain Ready to Connect. Catalogue targets are READY TO CONNECT until credentials and scanners are configured.

  • Architecture

    Verified

    ValarIQ operates as a control plane between autonomous systems and consequential execution. It does not execute payments or hold customer funds. Core authority and policy decisions fail closed when required inputs cannot be evaluated.

    Limitation. Customer execution stacks remain outside ValarIQ boundary.

  • Authentication and authorisation

    Verified

    Session-based UI authentication, scoped Bearer API keys, server-side workspace roles and tenant controls operate in production. SSO/SAML and SCIM are not activated.

    Limitation. SSO/SCIM inactive; owner login requires manual verification.

  • Context Assurance

    Verified

    The deterministic core verifies configured provenance, integrity, freshness, completeness and consistency requirements used in autonomous-action decisions.

    Limitation. Context Assurance does not independently guarantee that source information is factually true. Real external evidence providers remain Foundation or Ready to connect.

  • Evidence integrity

    Verified

    Decision evidence is cryptographically signed within implemented scope. Legacy envelope formats remain readable and are labelled when unbound.

    Limitation. Not claimed absolutely immutable; independent timestamping Coming.

  • Ops Chat (Insights)

    Verified

    Read-only Insights chat answers estate questions from live workspace records (agents, Discover, approvals, policy mode, recent control pressure). Unknown prompts refuse rather than invent.

    Limitation. Not an LLM assistant; no write actions or payment execution through chat.

  • PostgreSQL and RLS

    Verified

    Production uses a managed relational database with tenant-scoped row-level security. Automated tenant-isolation regression tests have passed.

    Limitation. Multi-region database resilience not implemented.

  • Roadmap honesty

    Verified

    The capability registry is the public source of truth. LIVE, FOUNDATION, READY TO CONNECT and COMING reflect current production evidence.

    Limitation. Staging-only modules must not appear Live on production without release.

  • Team roles and invitations

    Verified

    Workspace owners and admins can invite members, change roles (owner, admin, approver, viewer) and revoke access. Role checks are enforced server-side on sensitive APIs.

    Limitation. SSO/SCIM not activated; first-party email/OTP remains the Live path.

  • Encryption

    Ready to Connect

    HTTPS operates in production. Sensitive backups are encrypted.

    Limitation. Universal storage encryption, customer-managed keys, KMS or HSM not verified.

  • Incident response

    Ready to Connect

    Incident workflows, containment, release records and operational procedures exist.

    Limitation. Contractual SLA, RTO and RPO commitments are not approved.

  • Monitoring

    Ready to Connect

    Application, decision, worker, queue, containment and operational visibility exist.

    Limitation. Independent external uptime monitoring and formal on-call coverage remain unverified unless activated.

  • Retention

    Ready to Connect

    Retention fields and workspace practices exist.

    Limitation. Legally approved and fully automated retention schedule not verified.

  • SDLC and dependencies

    Ready to Connect

    Tests, typecheck, bounded lint gate, dependency audit, claims checking and secret scanning operate before release.

    Limitation. Hosted CI, enforced branch protection and continuous independent audit remain unverified. Working-tree promotion was corrected in Batch 0 (commit 84f9c99, 2026-08-29).

  • Availability and HA

    In Progress

    Single-region hosted deployment.

    Limitation. Do not claim multi-region, multi-replica HA or contractual uptime.

  • Certifications

    In Progress

    No ISO 27001, SOC 2 or other certification.

    Limitation. Framework mappings are not certification.

Need the private evidence pack?

Design-partner diligence includes custody, backup and deeper operational evidence on request.

hello@valariq.com · Capabilities · Architecture

Request access