Valta Docs
Security overview
- API keys are hashed at rest and can be revoked instantly.
- Agent wallets are isolated per
agentId. - Session management follows Better Auth defaults on the Valta web app.
- Valta itself is not SOC 2 certified. Infrastructure runs on hosts that publicly state SOC 2 Type II compliance for their own platforms — Vercel (application hosting) and Supabase (database).