SECURITY

Attorney-client privilege protected by design

Legal data demands more than checkbox compliance. Valryn is built with tenant isolation, encryption, and audit logging from the database up — so your firm can show clients exactly how their information is handled.

Encryption in transit and at rest

All traffic is protected by TLS 1.3. Data at rest — including call recordings, transcripts, and case facts — is encrypted with AES-256. Secrets and API keys live in a managed vault with automatic rotation.

Row-level security (RLS)

Every table in our PostgreSQL database is protected by row-level security policies that enforce tenant isolation. A firm can only read and write its own rows — enforced at the database layer, not at the application layer where bugs are common.

Role-based access control

Four-tier RBAC: super_admin, admin, manager, agent. Sensitive actions (billing, team management, scoring profile changes) are restricted to admin+ roles. Role enforcement happens both in the API middleware and inside RLS policies.

Audit logging

Every sensitive action — case assignments, exports, recording access, billing changes — is logged with user, timestamp, IP, and change diff. Audit trails are immutable and exportable for compliance reviews.

Attorney-client privilege

Call recordings and transcripts are treated as privileged material. Access is gated by role and firm scope; downloads are audit-logged. We never use your firm's data to train external models.

Compliance posture

We are actively building toward SOC 2 Type II. Our architecture is HIPAA-ready — BAAs available on enterprise plans. We honor data deletion requests under GDPR/CCPA and operate on least-privilege cloud infrastructure.

Questions about our security posture?

Enterprise plans include security reviews with your IT team and access to our compliance documentation (SOC 2 progress reports, data processing agreements, BAAs). Reach out through the demo form and we'll schedule time with our engineering lead.