Valta Docs

Security overview

  • API keys are hashed at rest and can be revoked instantly.
  • Agent wallets are isolated per agentId.
  • Session management follows Better Auth defaults on the Valta web app.
  • Valta itself is not SOC 2 certified. Infrastructure runs on hosts that publicly state SOC 2 Type II compliance for their own platforms — Vercel (application hosting) and Supabase (database).

Next steps