Data discipline
Collect less.
Early-access records contain the information a visitor submits, a short first-party campaign label, consent choices, and delivery state. The application does not add an IP address, user agent, analytics identifier, or full referring URL to that record.
Transport and storage
Protect the path.
The site is delivered over HTTPS with managed certificates and an HSTS policy. Intake data is stored in Azure Table Storage, which is encrypted at rest by Azure using Microsoft-managed keys.
Browser boundary
Keep the surface narrow.
A restrictive Content Security Policy, frame protection, cross-origin isolation, locked browser permissions, same-origin APIs, and an explicit deployment allowlist reduce the public surface. No third-party analytics or advertising scripts are loaded.
Operational response
Detect and recover.
Regional availability checks run every five minutes. API failures and stale or failed email deliveries raise operational alerts. Every release must pass browser, performance, security, API, and live production checks.
The trust model
Control made visible through review.
Confidence is created through visible care. What is entrusted is received clearly, reviewed deliberately, and returned with greater clarity, never with less context.
- 01
Received with custody
Valuable context enters a protected environment with provenance and condition made explicit from the start.
- 02
Reviewed in presence
Evidence, approval, and auditability keep professional judgment at the center instead of replacing it.
- 03
Returned with clarity
What matters is preserved, organized, and made more usable without weakening control or accountability.
Regulation-aware by design
Designed for firm-governed environments.
Product controls are being designed for configurable access, review, evidence, and approval within firm-governed environments. Suitability and compliance depend on each firm’s registration, policies, systems, configuration, and operating procedures.
ValaisOS is not presented as a compliance archive, records-management system, or substitute for a firm’s legal, compliance, information-security, records-management, or technology review.
The public site uses Microsoft Azure services. Microsoft maintains independent audit reports and certifications for specific services under programs such as SOC and ISO, but scope varies by service and report. Azure hosting does not make ValaisOS certified, and we do not present inherited cloud assurance as a ValaisOS compliance claim.
Review Microsoft’s Azure compliance documentation.
Advisory questions
Considering ValaisOS in a firm-governed environment?
Our dedicated FAQ addresses repositories, firm records, permitted AI providers, evidence, policy alignment, and the limits of technology in a firm’s compliance program.
Review frequently asked questions.
Responsible disclosure
If you believe you have found a security issue affecting this public site, email hello@valaisos.com with “Security report” in the subject. Include the affected URL, a concise description, reproduction steps, and potential impact.
Please avoid accessing or changing information that is not yours, disrupting service, or using automated testing that could affect other visitors. We will acknowledge a credible report and coordinate next steps, but we do not currently operate a public bug-bounty program.
We will not pursue legal action against researchers who, in good faith, report a vulnerability affecting this public site to hello@valaisos.com, avoid privacy violations and service disruption, do not access or keep data beyond what is needed to demonstrate the issue, and give us reasonable time to respond before any disclosure. This applies to the public website only.
Scope boundary
This Trust Center covers the public website, its early-access form, first-party aggregate measurement, and related notification operations. Product and private-preview controls will be documented separately before those environments accept participants or sensitive client information.