1. Trust Services Criteria
Valorenode's SOC 2 Type II examination covers the Security, Availability, and Confidentiality trust services criteria over a 12-month observation period. Our autonomous AI engine, deep-web retrieval agents, and multi-tenant review pipeline are evaluated as a unified control environment operated from Lisbon, Portugal.
2. Continuous Trust Monitoring
We operate real-time trust monitoring across all production systems. Automated control checks run every 15 minutes validating: RLS policy integrity, encryption key rotation status, API gateway rate limits, and audit log append-only immutability. Anomalies trigger immediate PagerDuty escalation to our solo-founder engineering on-call rotation with mean-time-to-acknowledge under 15 minutes.
- 99.99% crawler fleet availability (verified Q2 2026)
- Zero critical control failures in current observation period
- Quarterly penetration testing by independent EU security firm
3. Continuous Delivery Architecture
Our CI/CD pipeline enforces automated security gates before any deployment. Every merge to main triggers: dependency vulnerability scanning (Snyk), static analysis (ESLint security rules), infrastructure-as-code validation, and staged canary deployment with automatic rollback on error-rate spikes above 0.1%. Deployment frequency averages 4.2 releases per week with a change failure rate below 2%.
4. Access Control Metrics
Production access is limited to two authenticated engineers with hardware security keys (FIDO2). All access sessions are recorded with timestamp, source IP, and action scope. Privileged access reviews occur monthly. Service role key usage is restricted to audited background jobs with explicit organization_id scoping per our PROMPT.md security architecture.
5. Report Access
The full SOC 2 Type II report is available to Pro and Agency / Scale customers under NDA. Request access via /contact with your organization details and we will provision secure document delivery within 2 business days.