Security
Built to sit in the path of money.
ValarIQ is designed as critical control infrastructure. Security, availability, and evidence integrity are part of the product — not afterthoughts.
Architecture
Control plane positioning
ValarIQ is an independent authorisation layer between autonomous agents and financial infrastructure. It does not execute payments or hold customer funds.
Fail-closed default
When identity, authority, or policy cannot be evaluated, the default outcome is deny. High-risk money movement stops if the control plane is unavailable. Enterprise HA, regional failover, and degraded-mode patterns are on the roadmap — see Architecture.
Workspace isolation
Workspace-level logical isolation. Agent certificates, policy configuration, approvals, and evidence are scoped to the workspace with role-based access control.
Identity & Access
Workspace accounts
Hashed passwords. Roles include owner, admin, approver, and viewer. Session cookies issued only after authentication over HTTPS.
Gateway API keys
Scoped API keys (vq_live_…) for agent runtime integration. Keys can be rotated and revoked per workspace.
Agent identity
Cryptographic agent certificates with fingerprints, explicit scopes, Authority Profiles, and revocation. Key material is held under controlled custody with documented backup procedures.
SSO / SAMLRoadmap
On the roadmap for institution pilots. Not yet shipped.
Data
Data at rest
Application data is stored in encrypted persistent storage with workspace-level logical isolation, controlled access, and documented backup and recovery procedures.
Evidence integrity
Decisions produce signed Evidence Envelopes with cryptographic integrity — agent, authority, policies evaluated, decision, approver, and trail.
Key custody
Session signing and agent trust material are environment-separated. Operators maintain encrypted offline backups. Detailed custody procedures are available under NDA for design-partner diligence.
Data residencyRoadmap
Enterprise option for dedicated deployment and region selection. Standard SaaS runs in UK/EU infrastructure.
Production databaseRoadmap
Managed relational database (PostgreSQL) for production multi-tenant workloads is on the enterprise readiness roadmap.
SDLC
Dependency management
Locked dependencies. Regular updates for known vulnerabilities in production dependencies.
Code review
All changes reviewed before merge. Security-sensitive paths (auth, crypto, policy engine) require explicit review.
Secrets handling
No secrets in source control. Environment variables for session signing, API keys, and trust material.
Operations
Transport security
All production traffic served over HTTPS. TLS termination at the edge.
Backups & recovery
Encrypted offline backups with documented restore procedures. RTO/RPO targets defined for design-partner and enterprise deployments.
Monitoring
Decision volume, approval queue depth, and error rates monitored. Workspace kill switch for emergency agent freeze.
Incident response
Documented escalation path. Design partners receive direct founder access during pilot.
Assurance
We are honest about current state versus roadmap. Early diligence should use this page alongside a pilot statement of work.
ISO 27001 readinessIn progress
In progress. Control framework mapping underway. Not yet certified.
SOC 2Roadmap
Planned after paying logos. Not yet started.
Vendor questionnaires
Available for design-partner pilots. Use this page + pilot SOW for early diligence. Implementation detail belongs in the diligence pack — not public marketing.
Trust & contact
Security and diligence questions: hello@valariq.com. Related: Architecture · Company · Privacy.