Trust & Security

Built for regulated operators.

Valix is built with end-to-end encryption, immutable audit logs, and role-based access control. Every transaction logged. Every change traceable. Your data stays yours.

Controls

Security controls across the full stack

Access controls, encryption, change management, and incident response are built into the platform — with immutable audit logs across every layer.

Valix security controls overview

Encryption

TLS 1.3 in transit, AES-256 at rest

All data moves encrypted. Keys are rotated quarterly and stored in hardware security modules. Access to encryption infrastructure requires multi-factor authentication and is logged.

General-ledger audit trail
Role-based permissions matrix

Access

Role-based permissions down to the transaction

Assign permissions by property, entity, or function. Every user action and every AI decision is timestamped and immutable. Compliance teams can export full audit trails for regulatory review.

Security & compliance

Direct answers. No hedging.

Common questions from CISOs, auditors, and procurement teams. Anything not covered here, our security team will answer under NDA.

What happens in a breach?

We notify affected parties within 24 hours and file required disclosures. All data is encrypted at rest and in transit, limiting exposure. Our incident response plan is tested quarterly with tabletop exercises.

How do you approach security controls?

Security is built around least-privilege access, encryption in transit and at rest, and immutable audit logs on every financial action. We're happy to walk enterprise security teams through our current controls in detail under NDA.

Do you handle GDPR and CCPA?

We comply with both frameworks. Tenants and residents have rights to access, correction, and deletion. Data processing agreements are standard for all accounts. EU hosting available for enterprise customers.

Can we audit your logs?

Every financial transaction is logged with timestamp, user, IP, old-value and new-value. You can export audit trails from the compliance dashboard. Third-party auditors can request access under controlled conditions.

What about backups and recovery?

Data is backed up every 6 hours across geographically separated regions. Recovery time objective is under 4 hours; recovery point objective is 6 hours. We test restores monthly.

How is access controlled?

47 permission codes across 10 role types (RBAC). Enterprise customers get SSO via SAML or OIDC. MFA is required for all admin roles. Session tokens expire after 30 min of inactivity; impersonation tokens expire after 30 min total.