Encrypted everywhere
All traffic to and from the gateway and control plane is encrypted in transit with TLS, and stored data is encrypted at rest on managed infrastructure.
Valite sits between your application and your model providers. That position demands a specific posture: redact credentials, isolate tenants, prove every change, and keep you in control of your data.
All traffic to and from the gateway and control plane is encrypted in transit with TLS, and stored data is encrypted at rest on managed infrastructure.
Credential headers — API keys, cookies, auth tokens — are redacted from every log record before it is written. Your provider API keys pass through to the provider and are never stored.
Every record is scoped to your organization across both the control plane and the call log. Reads and writes are checked against organization membership on every request.
Valite API keys are stored hashed and scoped to a single organization, following least privilege: keys authenticate gateway traffic, while account operations require an authenticated dashboard session.
Policy changes activate through shadow and canary stages with quality and error-rate tripwires, and roll back automatically to the exact prior configuration when a threshold fails.
Replay and calibration jobs run only within budgets set in advance, so offline evaluation can never run away with spend.
Captured traffic is used solely to profile, replay, evaluate, and optimize your own workloads. We do not sell your data and we do not use it to train models.
Ask us to delete your captured traffic and account data and we will — completely, including replay artifacts derived from it.
Enterprise customers can run Valite in a private deployment, including on-premises, so captured traffic never leaves infrastructure you control.
Found a vulnerability, or need our security documentation for a review? Email hello@valite.ai — security reports are triaged ahead of everything else.