ValarIQ

Security

Built to sit in the path of money.

ValarIQ is designed as critical control infrastructure. Security, availability, and evidence integrity are part of the product — not afterthoughts.

Architecture

  • Control plane positioning

    ValarIQ is an independent authorisation layer between autonomous agents and financial infrastructure. It does not execute payments or hold customer funds.

  • Fail-closed default

    When identity, authority, or policy cannot be evaluated, the default outcome is deny. High-risk money movement stops if the control plane is unavailable. Enterprise HA, regional failover, and degraded-mode patterns are on the roadmap — see Architecture.

  • Workspace isolation

    Workspace-level logical isolation. Agent certificates, policy configuration, approvals, and evidence are scoped to the workspace with role-based access control.

Identity & Access

  • Workspace accounts

    Hashed passwords. Roles include owner, admin, approver, and viewer. Session cookies issued only after authentication over HTTPS.

  • Gateway API keys

    Scoped API keys (vq_live_…) for agent runtime integration. Keys can be rotated and revoked per workspace.

  • Agent identity

    Cryptographic agent certificates with fingerprints, explicit scopes, Authority Profiles, and revocation. Key material is held under controlled custody with documented backup procedures.

  • SSO / SAMLRoadmap

    On the roadmap for institution pilots. Not yet shipped.

Data

  • Data at rest

    Application data is stored in encrypted persistent storage with workspace-level logical isolation, controlled access, and documented backup and recovery procedures.

  • Evidence integrity

    Decisions produce signed Evidence Envelopes with cryptographic integrity — agent, authority, policies evaluated, decision, approver, and trail.

  • Key custody

    Session signing and agent trust material are environment-separated. Operators maintain encrypted offline backups. Detailed custody procedures are available under NDA for design-partner diligence.

  • Data residencyRoadmap

    Enterprise option for dedicated deployment and region selection. Standard SaaS runs in UK/EU infrastructure.

  • Production databaseRoadmap

    Managed relational database (PostgreSQL) for production multi-tenant workloads is on the enterprise readiness roadmap.

SDLC

  • Dependency management

    Locked dependencies. Regular updates for known vulnerabilities in production dependencies.

  • Code review

    All changes reviewed before merge. Security-sensitive paths (auth, crypto, policy engine) require explicit review.

  • Secrets handling

    No secrets in source control. Environment variables for session signing, API keys, and trust material.

Operations

  • Transport security

    All production traffic served over HTTPS. TLS termination at the edge.

  • Backups & recovery

    Encrypted offline backups with documented restore procedures. RTO/RPO targets defined for design-partner and enterprise deployments.

  • Monitoring

    Decision volume, approval queue depth, and error rates monitored. Workspace kill switch for emergency agent freeze.

  • Incident response

    Documented escalation path. Design partners receive direct founder access during pilot.

Assurance

We are honest about current state versus roadmap. Early diligence should use this page alongside a pilot statement of work.

  • ISO 27001 readinessIn progress

    In progress. Control framework mapping underway. Not yet certified.

  • SOC 2Roadmap

    Planned after paying logos. Not yet started.

  • Vendor questionnaires

    Available for design-partner pilots. Use this page + pilot SOW for early diligence. Implementation detail belongs in the diligence pack — not public marketing.

Trust & contact

Security and diligence questions: hello@valariq.com. Related: Architecture · Company · Privacy.