Procurement and security questionnaire answers for ValGuard. Use this with the main Trust page, Security, DPA, and SLA. Last aligned with Trust review: 2026-10-05.
One-page answers
| Question | Answer |
|---|---|
| What is the product? | OpenAI-compatible validation and policy proxy with optional playbooks. Not a workflow engine or connector catalog. |
| Local / OSS runtime? | No. Hosted SaaS default; Enterprise self-host in your VPC under license. |
| Where does data go? | Hosted: subprocessors on subprocessors. Self-host: your VPC; license heartbeat without AI payloads. |
| Payload retention? | Off by default. If enabled, plan caps apply (see Trust / Privacy). |
| Certifications? | Benchmarks and methodology public. SOC 2 / pentest summaries on request under NDA. Not claimed as public badges here. |
| Outage behavior? | Fail closed. Direct provider fallback bypasses rules; your app owns that choice. |
| Exit / portability? | Playbook JSON export (valguard-playbook-template/1, optional validators); per-agent validators API; audit export. No org-wide policy file yet. |
Diligence links
- Trust (data flow, streaming, failure modes)
- Security reviewer checklist
- Published evidence
- EU AI Act mapping (engineering)
- Regulated VPC reference architecture
- Contact / security@valguard.ai
Commercial packaging
| Path | When |
|---|---|
| Free → Growth | Shadow evaluation and production enforce on SaaS |
| Production | Higher SLA tier; see pricing and SLA |
| Enterprise | Self-host, longer retention options, license |
Exact SKUs and order forms come from sales; this page does not override a signed agreement.
What we will not claim
- That ValGuard alone makes you HIPAA, PCI, or AI Act compliant
- A free Docker evaluation that never sends data to ValGuard or a provider
- Silent fail-open when the proxy is down
Next step
Send the Trust + Security links to your reviewer, or contact for NDA assessment artifacts.