SECURITY
Attorney-client privilege protected by design
Legal data demands more than checkbox compliance. Valryn is built with tenant isolation, encryption, and audit logging from the database up — so your firm can show clients exactly how their information is handled.
Encryption in transit and at rest
All traffic is protected by TLS 1.3. Data at rest — including call recordings, transcripts, and case facts — is encrypted with AES-256. Secrets and API keys live in a managed vault with automatic rotation.
Row-level security (RLS)
Every table in our PostgreSQL database is protected by row-level security policies that enforce tenant isolation. A firm can only read and write its own rows — enforced at the database layer, not at the application layer where bugs are common.
Role-based access control
Four-tier RBAC: super_admin, admin, manager, agent. Sensitive actions (billing, team management, scoring profile changes) are restricted to admin+ roles. Role enforcement happens both in the API middleware and inside RLS policies.
Audit logging
Every sensitive action — case assignments, exports, recording access, billing changes — is logged with user, timestamp, IP, and change diff. Audit trails are immutable and exportable for compliance reviews.
Attorney-client privilege
Call recordings and transcripts are treated as privileged material. Access is gated by role and firm scope; downloads are audit-logged. We never use your firm's data to train external models.
Compliance posture
We are actively building toward SOC 2 Type II. Our architecture is HIPAA-ready — BAAs available on enterprise plans. We honor data deletion requests under GDPR/CCPA and operate on least-privilege cloud infrastructure.
Questions about our security posture?
Enterprise plans include security reviews with your IT team and access to our compliance documentation (SOC 2 progress reports, data processing agreements, BAAs). Reach out through the demo form and we'll schedule time with our engineering lead.