Security

Compliance evidence usually decays. Ours is a record that can’t be quietly rewritten.

You’re trusting us with the record of your security program: the statuses, evidence, and documents behind your affirmations. Here is what we built so that record holds up.

The record can't be edited after the fact.

What usually happens: histories live in ordinary, editable tables, and get cleaned up before an audit.

Every sensitive action lands in an append-only activity log: sign-ins, status changes, evidence operations, exports, billing events. The log is enforced at the database level; not even our own application code can rewrite or delete history.

Evidence goes straight to private storage.

What usually happens: files pass through the application and sit on web servers along the way.

Files upload directly to private storage over one-time signed URLs. They never transit or live on our web servers, and nothing in the bucket is public. Every file is verified server-side after upload: type allow-list, size caps, and content checks that reject files masquerading as another format. Downloads are short-lived signed links served from a separate domain, isolated from the application.

Deletion is yours to trigger, and it's real.

What usually happens: “delete” hides the data rather than removing it, and canceling strands what you built.

Canceling never strands your work: your workspace stays readable and fully exportable for 90 days, and reactivating within that window restores everything. After 90 days it is permanently deleted. Deletion on your own initiative is available anytime: owner-only, name-typed confirmation, live two-factor code. When you delete, we delete — files, records, history.

When your workspace is deleted, its data is removed from live systems immediately; residual copies in our encrypted backups age out completely within 30 days.

We stay outside your CUI boundary, on purpose.

What usually happens: the tool takes the covered data in, and inherits your compliance boundary with it.

Never upload CUI. Valontir is built to store evidence about your controls (policies, screenshots, scan summaries), not the covered information those controls protect. Upload surfaces remind you; our terms prohibit it. We are not a FedRAMP-authorized environment and don’t claim to be: by design, we operate outside your CUI boundary, which is what makes a platform at this price possible.

Questions, or something to report? support@valontir.com. We commit to acknowledging reports within 2 business days.

Hosting region and every sub-processor are listed in the privacy policy.