Security
Approach
VALO Research treats security as a system property: minimise authority, constrain effect paths, preserve evidence and fail closed where a governed consequence requires an authorization decision.
Access
Administrative and service access should follow least-privilege principles. Credentials and secrets must not be embedded in public source or client-side code.
Data
Data collection should be minimised to what the service needs. Sensitive or customer data must be separated from public demo data where the service handles both.
Software and infrastructure
Dependencies, deployment paths and infrastructure are expected to be controlled and reviewable. Security claims apply only to the systems and versions for which they are actually evidenced.
HEIMEL
Where HEIMEL is deployed as a consequence boundary, authorization is evaluated at the governed effect path. NO_DIRECT_EFFECT_PATH is a design invariant for deployments that explicitly claim conformance; it is not a blanket claim about every VALO web surface.
Incidents
Suspected security incidents are triaged according to impact and scope. Contractual notification duties for customer data are governed by the applicable agreement and DPA.
No certification claim
This page does not claim ISO, SOC 2 or other certification unless a specific current certification is explicitly identified.
Report a vulnerability
Use the Responsible Disclosure process or contact njaal@valoresearch.org.