01
Access control
Access is scoped by organisation, role, and service permissions. Protected credentials, tenant boundaries, and selected administrative and API-key actions are audited as part of the service's operational controls.
Security and compliance
A clear view of data handling, deployment, regulatory posture, and service continuity.
01
Access is scoped by organisation, role, and service permissions. Protected credentials, tenant boundaries, and selected administrative and API-key actions are audited as part of the service's operational controls.
02
Supported public and service connections use encrypted transport. Sensitive credentials are encrypted at rest, with storage and key-management controls applied according to the relevant data class and service.
01
Where is customer data hosted and stored?
VALAR's default production hosting runs in EU-based cloud regions. Other regions can be provided on request, subject to the applicable service configuration and agreement.
02
What is Valar's ITAR/EAR posture?
VALAR's standard terms address applicable export-control, sanctions, embargo, and European Union and Spanish dual-use obligations. Controlled technical data and government-classified information require an expressly authorised Order and agreed safeguards. Contact us to discuss controlled-data requirements.
03
What certifications and attestations does Valar hold?
VALAR operates documented technical and organisational safeguards across access control, protected secrets, tenant separation, monitoring, and deployment. Specific certifications, control frameworks, and customer security commitments are provided where applicable in the Order, DPA, or security exhibit.
04
What deployment options are available?
VALAR is delivered as a managed hosted service on containerised cloud infrastructure. Production releases pass database-migration checks and use immutable release tags for rollback. Data export and portability are available under the applicable agreement.
05
How long is customer data retained?
Retention depends on the type of data. Our Privacy Policy defines periods for account, transaction, marketing, analytics, and support data; production application logs are retained for 30 days. On exit, customer data can be exported and is deleted after the retrieval period, subject to legal, security-log, DPA, and backup-rotation requirements.
06
Which sub-processors handle customer data?
The applicable DPA identifies each subprocessor's function, data categories, processing locations, transfer mechanisms, and change-notification terms. Our service architecture uses cloud infrastructure, managed messaging, hosted application delivery, and observability providers; website analytics runs only after consent.
40.4378° N, 3.6795° W
Maria de Molina 39, 28006 Madrid, Spain
© VALAR SPACE, S.L. 2022 - 2026. All rights reserved.