VALO Research

Security

Effective 26 September 2026 · Operator: Njål Gaute Solland

Approach

VALO Research treats security as a system property: minimise authority, constrain effect paths, preserve evidence and fail closed where a governed consequence requires an authorization decision.

Access

Administrative and service access should follow least-privilege principles. Credentials and secrets must not be embedded in public source or client-side code.

Data

Data collection should be minimised to what the service needs. Sensitive or customer data must be separated from public demo data where the service handles both.

Software and infrastructure

Dependencies, deployment paths and infrastructure are expected to be controlled and reviewable. Security claims apply only to the systems and versions for which they are actually evidenced.

HEIMEL

Where HEIMEL is deployed as a consequence boundary, authorization is evaluated at the governed effect path. NO_DIRECT_EFFECT_PATH is a design invariant for deployments that explicitly claim conformance; it is not a blanket claim about every VALO web surface.

Incidents

Suspected security incidents are triaged according to impact and scope. Contractual notification duties for customer data are governed by the applicable agreement and DPA.

No certification claim

This page does not claim ISO, SOC 2 or other certification unless a specific current certification is explicitly identified.

Report a vulnerability

Use the Responsible Disclosure process or contact njaal@valoresearch.org.