Trust & governance

Control should be visible in the workflow.

Valentry is designed for regulated insurance work where access, versions, decisions, evidence and report integrity must remain clear long after the task is complete.

Valentry badge
AccessRole · organisation · assignment
AuditImportant actions recorded
VersionsAnalysis and report integrity
AI reviewHuman decision remains visible
Product control model

Security is not a badge row. It is how work is allowed to happen.

Valentry applies control through permissions, versioning, audit events, governed review and protected report access. Deployment-specific architecture and contractual commitments are confirmed during implementation.

01 / ACCESS

Role-based visibility

A user should access a case only when ownership, organisation, assignment or administrative permission allows it.

02 / TRACEABILITY

Immutable audit events

Important login, case, file, analysis, review, report and administrative actions should remain recorded and attributable.

03 / VERSIONING

No silent overwrites

Completed analyses create new versions. Final reports remain immutable and tied to the exact analysis version used.

04 / REPORTS

Controlled downloads

Users should be authenticated, authorised for the case and limited to reports that are available and not revoked.

05 / DATA

Protected client information

User credentials, personal information, insurance documents, analysis results, reports and organisation data are protected by design.

06 / AI

Human review remains explicit

Reviewers can approve, reject, request information and record quality or compliance concerns against the relevant version.

Clear disclosure: this website describes intended product controls and requirements. It does not claim ISO 27001, SOC 2 or another third-party certification. Hosting, encryption, retention, backups, incident procedures and data-processing terms must be confirmed for the production deployment.
Responsibility matrix

The right control for the right role.

This simplified matrix shows the role separation between standard users, reviewers, organisation administrators and platform administrators.

CapabilityStandard userReviewerOrganisation adminPlatform admin
Create and manage permitted casesYesYesOrganisation scopePermitted scope
Upload and categorise documentsYesYesOrganisation scopePermitted scope
Approve or reject analysisNot by defaultYesRole dependentRole dependent
Mark reports finalIf permittedIf permittedIf permittedIf permitted
Manage organisation usersNoNoYesYes
Manage prompts, schemas and templatesNoNoConfigured scopeYes
View audit and job monitoringOwn activityRelevant workOrganisation scopeAdministrative scope
AI governance

Assistance without invisible authority.

The model should show what documents were used, which workflow and version produced the output, what information is missing and who approved the final client-facing result.

Human judgement is not a hidden assumption.It is a visible step with a named reviewer decision and a linked version.
01
Eligibility check

Confirm access, required information, documents, credits and that no conflicting analysis is running.

Before start
02
Visible progress

Show queued, extracting, processing, analysing, validating, saving and report-generation stages.

During work
03
Structured result

Present policy detail, exclusions, warranties, gaps, risks, recommendations, missing information and confidence context.

Reviewable
04
Reviewer decision

Approve, approve with changes, reject or request more information with notes and quality concerns.

Human control
05
Version-locked report

Generate the report from a selected analysis version and preserve every previous report version.

Final proof
Security FAQ

Ask the harder questions early.

Production trust depends on verified implementation details, not only polished interface copy.

No ISO 27001, SOC 2 or other third-party certification claim is made on this website. Independent assurance is stated only when formally verified.

Role and permission management, organisation boundaries, assignment and administrative access are stated platform requirements. Exact permission sets are configured and tested during implementation.

Completed analysis versions should not be edited, final reports should not be overwritten and significant audit records should remain protected from alteration.

The workflow includes eligibility checks, visible progress, structured results, versioning, reviewer decisions and a rule that client-facing advice remains subject to authorised human review.

This static website does not specify a production hosting region or provider. Hosting location, subprocessors, encryption, backups, retention and incident processes must be documented in the production agreement.

The platform uses POPIA-aware handling and protection of personal information. Legal compliance also depends on implemented controls, contracts, operator relationships and each organisation’s own lawful processing practices.

Bring your compliance questions to the demo.

A serious product conversation should include permissions, audit events, versioning, AI review, report control, hosting and data-processing responsibilities — not avoid them.

Purpose-built for insuranceHuman-reviewed AIConnected by design