About

Built for the shops that keep the defense supply chain running. Compliance software sized for the U.S. defense suppliers who actually do the work.

Most of the U.S. defense supply chain is small: machine shops, electronics builders, engineering firms with fifteen to a hundred people and no security team. They carry the same NIST SP 800-171 obligations as a prime, on a fraction of the budget, and the tools built for them were designed for someone else. Valontir is the workspace where a small supplier’s compliance program lives: every requirement, every piece of evidence, every document, always current.

Why we built this

Compliance for a small shop usually goes one of two ways. A consultant produces a System Security Plan for five figures, and it starts going stale the day it arrives. Or the quality manager builds a spreadsheet, and the program lives in one person’s head. Either way, the moment a prime sends a questionnaire or the annual affirmation comes due, someone reverse-engineers the truth from a binder that describes a company that no longer exists.

We built Valontir because that gap is not a knowledge problem. Small shops know their systems. It is a maintenance problem, and maintenance is what software is for. Track the 320 assessment objectives as the assessor sees them, hash the evidence the moment it lands, compute the score from the official weights, and generate the documents from the live workspace, so the answer is already there when someone asks.

How we work

Evidence first.

Nothing in the product, and nothing on this site, is a claim without something behind it.

Plain English.

Written for a forty-person shop, not a security operations center.

Always current, never point-in-time.

A score that moves when your program moves.

Honest scope.

We keep your compliance evidence, not your controlled data. We make you assessment-ready. We do not certify anyone, and we say so.

The founder

Conference audience
Founder presenting on stage

Presenting original ICS vulnerability research · industrial security conference, 2024

Nicolas Cano · Founder

Security researcher with a background in vulnerability analysis, focused on operational technology and the industrial systems behind manufacturing and critical infrastructure.

For years my work has been finding security flaws in industrial control systems: the controllers, software, and equipment that run factory floors, energy systems, and other critical infrastructure. That means locating the weaknesses in those systems, analyzing how they could be exploited, and getting them disclosed and fixed. Much of it was in service of large industrial and critical-infrastructure operators, and I was the primary person responsible for a weekly vulnerability intelligence product those organizations relied on to make real decisions.

Watching small defense suppliers carry a compliance burden built for enterprises, it was hard not to notice how much of the difficulty was avoidable. I turned toward the problem from the security research side, and that discipline is what Valontir is built on: claims backed by evidence, precise reading of what a standard actually requires, and a clear line between what a company says it does and what it can show. I know how the assessment methodology works, objective by objective, and I built Valontir to remove that difficulty: precise about the requirements, plain about what they mean, and honest about what it can and cannot do.

Where this is going

Every small U.S. defense supplier should be able to prove its security posture as easily as a large prime: without a security team, without a five-figure consultant, and without a binder that is stale by renewal. We are building the workspace where a shop’s compliance program actually lives, so that when someone asks, the answer is already there.

support@valontir.com

Put evidence behind your signature.

Valontir keeps your requirements, evidence, and score in one place, ready whenever a prime asks. We’re onboarding early customers deliberately.