1. Trust Services Criteria
Valorenode is building toward SOC 2 Type II alignment across the Security, Availability, and Confidentiality trust services criteria. Our multi-tenant review pipeline, encrypted credential vaulting, and audit logging are designed as a unified control environment operated from Lisbon, Portugal. A formal examination report is provided to qualifying customers when available under NDA.
2. Production Trust Monitoring
Production health is monitored through application status probes, database connectivity checks, and scheduled job dependencies (including crawl/scheduler paths). Alerts are reviewed by the founding engineering rotation. We do not publish unverified “fleet availability” percentages.
- Tenant-scoped data access with fail-closed isolation
- Encrypted payment method tokens (no full PAN storage)
- Audit trails for sensitive workspace actions
3. Delivery & Change Control
Changes ship through a modern CI-oriented workflow with compile checks, auth smoke verification, and release-gate audits before production promotion. Exact tooling and cadence evolve with the product — we avoid inventing release KPIs that are not independently attested.
4. Access Control
Production access is limited to authenticated operators. Privileged actions are expected to be auditable. Service roles used by background jobs must remain organization-scoped. Customers remain responsible for securing their own workspace credentials and reviewing AI drafts before publication.
5. Report Access
When a SOC 2 Type II report is available, Pro and Agency / Scale customers may request access under NDA via /contact. Until then, this page describes readiness posture — not a completed examination certificate.