Valistry

Trust

AI economics, without reading the work.

Valistry is built around usage and billing metadata. Prompts, completions, transcripts and source code stay outside the ledger.

  • Read-only
  • Open connectors
  • Encrypted credentials
  • model · claude-sonnet
  • promptrefused
  • tokens · 1,204 / 388
  • completionrefused
  • cost · $0.0132
  • source coderefused

The ledger · one record

metadata only
Provider · model
Anthropic · claude-sonnet
When
09:41:07 · Sep
How much
1,204 / 388 tokens
What it cost
$0.0132
How it went
ok · 812 ms
Whose
Support AI

Six fields. Content has no field to land in.

Economic and operational metadata comes inBusiness content is refused at the connector

The record

Everything one usage record holds.

This is the whole shape. A reviewer can check it against the open connectors.

Provider and model
Which vendor served the call, and which model
When
Timestamp and billing period
How much
Tokens, requests, seats or seconds, by the vendor's own meter
What it cost
Rate, currency and the reconciled amount
How it went
Status and latency
Whose
Account, project and the identifiers the vendor attaches

Never stored

The record has no place for content.

These six things cannot enter the ledger, because no field exists to hold them.

  • Prompts
  • Completions
  • Conversations
  • Transcripts
  • Documents
  • Source code

The absence is a shape, not a setting. A test fails the build if a content field is added.

The rules, and the evidence

Six things that are true of the product today.

Nothing here is a promise. Pick a rule; the evidence sits beside it.

Access

Read-only first

Each source asks for the narrowest access it supports, and no adapter may write to a provider.

The evidence

Each connector declares the URLs it may call. A call anywhere else is refused before it leaves, and every call made with a credential is written to an append-only log without its query.

Diligence

The answers a security review asks for.

Each one is what the software does today, checkable in the product or in the open connectors.

Sign-in
Supabase Auth, server-side. A magic link or a six-digit code, so there is no password for us to lose. Single sign-on is not built yet; ask and we will tell you where it sits.
Roles
Owner, admin and member. An admin manages sources and people; a member reads. Invites go by email, and a member can be removed.
Tenant isolation
Every query is scoped by organization, in one store the whole product reads through. Row level security is on, and only the server role holds a grant — anon and authenticated hold none.
Encryption
In transit and at rest. Connector credentials carry a second layer: AES-256-GCM under a master key, shown afterwards only as their last four characters.
What we never read
Prompts, completions, transcripts and source code. Not a setting: the usage record has no field for content, and a test fails the build if one is added.
Least privilege
Each connector declares the URLs it may call, and a call anywhere else is refused before the request leaves. Every call is logged without its query.
Data residency
Records sit in AWS us-east-1, in the United States. The company is registered in India. If your organization needs them elsewhere, say so before connecting a source.
Retention and deletion
Records live while your organization does. Deleting it deletes them; disconnecting a source stops new ones arriving. Our billing records and the connector call log outlive that, and the log holds a URL and a status, never a secret.
Sub-processors
Three, each named on the privacy notice with what it does: Supabase, Vercel, and Amazon Bedrock — which is given a computed result and never a prompt or a ledger row.
Incidents
We have had none. If we do, affected account owners hear from us with what happened, what was reached and what we changed.

A question this does not answer: hello@valistry.ai. Diligence is answered in writing.

Where we stand

What is certified, and what is not.

Every claim above is checkable in the product. These are the ones that need an auditor, and we have not been audited yet.

In place

In place today

Encrypted at rest and in transit. Credentials under AES-256-GCM with a master key the product never shows. Every connector call logged, without its query.

In place

Tenant isolation

Every query is scoped by organization. Row level security is on, and only the server role holds any grant.

Not yet

SOC 2 Type II

Not started. We will say so here the day it is, and name the auditor and the period.

Not yet

ISO 27001

Not started.

Not yet

Independent penetration test

Not commissioned. The endpoint allow-list and the absent content field are in the open source instead, which is evidence you can read today rather than a report you must request.

Processors are named on the privacy notice, and the records sit in AWS us-east-1.

Bring the metadata. Keep control of the content.

One read-only connection is enough to see the ledger. Diligence questions are answered in writing.