scanned Sep 4, 2026

Valiron

valiron.co

Valiron provides hybrid trust infrastructure for autonomous agents, combining on-chain reputation with behavioral analysis for intelligent trust routing.

52/100

Tier 3 · Agent-Accessible

Content answers39/100
Protocol plumbing81/10013 of 16 checks pass

Scored by asking 15 questions a buyer of a security product asks, then grading this site’s own pages: answered, hedged (partial or vague), or silent (no page answers it). How scoring works

This report is public. Own valiron.co? Claiming is free: crawl every page, re-audit as you fix, and track your score over time.

Sign in to claim

The fix queue

48 points sit between valiron.co and 100: 11 open questions and 3 missing protocol checks, ordered by estimated payoff.

Point estimates are per fix under scoring v2. They are not additive to a promised total.

01security · importance highGoes silent+7 content pts est.

Are you SOC 2 Type II certified, and can I download the audit report without signing an NDA?

What the pages say

No page on the site addresses this.

The fix

Create a dedicated security/compliance page that lists current certifications (e.g., SOC 2 Type II) and explains how prospects can request or download audit reports, including whether an NDA is required.

Where we looked: /docs, /docs/agents/IDENTITY.md, /skill/SKILL.md, /docs/agents/TRUST-MODEL.md, /llms.txt, /docs/agents/DASHBOARD.md, /docs/agents/API-REFERENCE.md, /llms-full.txt, /llms-full.txt, /docs/agents/SDK-REFERENCE.md

confidence high · grounding world-knowledge · weight 0.00 · Absent

02limits · importance mediumGoes silent+7 content pts est.

Your docs mention agent chains — what's the maximum number of chained trust gates allowed in a single session?

What the pages say

Valiron's website does not mention chained trust gates or a maximum number of chained trust gates in a single session. The documentation uses "chain" only as a blockchain network parameter and discusses "gated endpoints" (API endpoints protected by a single trust gate), not sequential/chained gate evaluations.

The fix

Add documentation clarifying whether multiple trust gates can be chained in a single session and what limits apply, or explicitly state that chaining is not supported.

Where we looked: /docs, /llms.txt, /skill/SKILL.md

confidence high · grounding synthesized · weight 0.00 · Absent

03migration · importance mediumGoes silent+7 content pts est.

Can I bulk-import existing agent identities from my current IAM provider, or do I have to re-provision each one manually?

What the pages say

No page on the site addresses this.

The fix

Add a documentation page or FAQ section covering migration from existing IAM providers, including whether bulk import via SCIM, CSV, or API is supported.

Where we looked: /auth.md, /skills/agent-identity.md, /docs/agents/QUICKSTART.md

confidence high · grounding synthesized · weight 0.00 · Absent

04support · importance mediumGoes silent+7 content pts est.

What's the guaranteed response time for Enterprise-critical tickets, and is it backed by a financial SLA?

What the pages say

No page on the site addresses this.

The fix

Create a dedicated Support or SLA page that specifies guaranteed response times for Enterprise-critical tickets and whether they are backed by financial credits or penalties.

Where we looked: /skills/trust-gate.md, /docs/agents/API-REFERENCE.md

confidence high · grounding synthesized · weight 0.00 · Absent

05integration · importance lowGoes silent+7 content pts est.

Does the Agent-Ready API support idempotency keys for POST requests, and what's the retry window before a key expires?

What the pages say

No page on the site addresses this.

The fix

Add documentation to the API reference clarifying whether idempotency keys are supported for POST requests and specifying any retry window or expiration behavior.

Where we looked: /docs/agents/API-REFERENCE.md, /docs/agents/API-REFERENCE.md, /llms.txt

confidence high · grounding world-knowledge · weight 0.00 · Absent

06limits · importance lowGoes silent+7 content pts est.

What exact HTTP status code and error payload does the middleware return when an agent hits the sandbox egress limit?

What the pages say

No page on the site addresses this.

The fix

Add documentation for sandbox egress limits, specifying the exact HTTP status code and JSON error payload the middleware returns when an agent exceeds them.

Where we looked: /docs/agents/QUICKSTART.md, /docs/agents/SANDBOX.md, /docs/agents/SDK-REFERENCE.md, /llms-full.txt, /llms-full.txt, /docs

confidence high · grounding synthesized · weight 0.00 · Absent

07operations · importance lowGoes silent+7 content pts est.

How long does an unused sandbox environment persist before automatic deletion, and is there a grace period to restore it?

What the pages say

No page on the site addresses this.

The fix

Add documentation covering sandbox environment persistence, automatic deletion policies for unused environments, and any grace periods or restoration procedures.

confidence high · grounding world-knowledge · weight 0.00 · Absent

08security · importance lowGoes silent+7 content pts est.

Can I bind multiple X.509 certificates to a single agent identity for rotation, or is it strictly one certificate per agent?

What the pages say

No page on the site addresses this.

The fix

Add documentation or a FAQ entry clarifying whether X.509/mTLS certificates are supported for agent authentication and if multiple certificates can be bound to a single agent identity for rotation.

confidence high · grounding world-knowledge · weight 0.00 · Absent

Hedged · 3 of 15 questions

A buyer gets something, then has to guess the rest. Expand any row for the evidence and the fix.

09Is there a free tier available, and what's the hard monthly limit on API calls before it cuts off?pricingHedges+2 pts est.

Is there a free tier available, and what's the hard monthly limit on API calls before it cuts off?

What the pages say

Yes, Valiron offers a Free tier that includes 3 gated endpoints and 5 sandbox tests per day. However, none of the retrieved chunks specify a hard monthly limit on API calls before cutoff.

The fix

Add the exact monthly API call hard limit (if any) to the Plans & Limits table on the pricing or SDK reference page.

Where we looked: /docs/agents/SDK-REFERENCE.md, /llms.txt, /llms.txt

confidence high · grounding synthesized · weight 0.70 · Vague

10If an agent fails a trust-gate check mid-chain, does the platform revoke its session token or only block that individual request?securityHedges+2 pts est.

If an agent fails a trust-gate check mid-chain, does the platform revoke its session token or only block that individual request?

What the pages say

When an agent fails a trust-gate check, Valiron blocks that individual request and returns a 403 `TRUST_GATE_DENIED` error. The retrieved chunks do not mention session tokens or any mechanism to revoke them.

The fix

Clarify in the trust-gate or SDK documentation whether a failed check invalidates any session or long-lived token, or explicitly state that each request is evaluated independently.

Where we looked: /docs/agents/SDK-REFERENCE.md, /skills/trust-gate.md

confidence medium · grounding synthesized · weight 0.65 · Vague

11How many predictive risk API calls are included in the Pro plan each month before overage charges apply?pricingHedges+2 pts est.

How many predictive risk API calls are included in the Pro plan each month before overage charges apply?

What the pages say

The retrieved chunks identify predictive risk as an operator analytics endpoint (`GET /operator/analytics/agents/{id}/prediction`) and describe Pro plan features, but they do not state how many predictive risk API calls are included in the Pro plan per month or what overage charges apply.

The fix

Add a pricing or plan-limits page that explicitly states monthly API call allowances and overage rates for predictive risk and other metered features.

Where we looked: /skill/SKILL.md, /docs/agents/SDK-REFERENCE.md, /llms.txt

confidence high · grounding synthesized · weight 0.70 · Vague

What the pages already answer cleanly

4 of 15. Answered with enough specificity for a buyer to act on. This is the bar the queue above is chasing.

integrationAnswered

Which languages have officially supported SDKs, and is the middleware compatible with Python FastAPI out of the box?

What the pages say

Valiron officially supports a TypeScript/JavaScript SDK distributed via npm as `@valiron/sdk`. Middleware is documented for JavaScript frameworks including Express, Fastify, Next.js, Hono, and Koa. Python and FastAPI are not mentioned as supported languages or frameworks.

Source: /llms-full.txt, /llms-full.txt, /llms-full.txt, /llms-full.txt, /docs, /docs/agents/QUICKSTART.md

confidence high · grounding synthesized · weight 0.95 · Answered

fitAnswered

Does the security assessment output a quantitative risk score, or does it provide a pass/fail result with remediation steps?

What the pages say

Valiron outputs both. The wallet and gate assessments return quantitative risk scores: a 0–100 trust `score`, a derived `risk` value (100 – score), and categorical `riskLevel` values such as LOW/MEDIUM/HIGH/CRITICAL or GREEN/YELLOW/RED. Simultaneously, the trust gate issues a pass/fail result via an `allow` boolean and a `route` decision (e.g., prod, sandbox, sandbox_only). Remediation guidance is provided through predictive-risk outputs that include a `recommendedPolicy`, `recommendedTests`, and human-readable `reasons`.

Source: /docs/agents/SDK-REFERENCE.md, /docs/agents/TRUST-MODEL.md, /docs, /docs/agents/API-REFERENCE.md, /docs/agents/DASHBOARD.md, /docs/agents/API-REFERENCE.md

confidence high · grounding synthesized · weight 0.95 · Answered

integrationAnswered

Does the E2E middleware require a reverse proxy, or can it deploy as an in-process sidecar alongside my existing API gateway?

What the pages say

The E2E middleware does not require a reverse proxy. It deploys as in-process middleware within your API backend (e.g., via Express, Next.js, Hono, or Koa adapters) and evaluates requests before they reach application handlers. Valiron also offers a separate Proxy Gateway (Pro) if you prefer a reverse-proxy deployment.

Source: /docs, /docs/agents/QUICKSTART.md, /docs/agents/SDK-REFERENCE.md, /docs/agents/SDK-REFERENCE.md

confidence high · grounding synthesized · weight 0.95 · Answered

operationsAnswered

In the dashboard, can I filter the audit log by both chain ID and individual trust-gate outcome at the same time?

What the pages say

No. The dashboard documentation refers to this feature as Call Logs and explicitly lists only two filters: time range (All time, Last 24h, 7 days, 30 days, 90 days) and pagination (50 entries per page). Filtering by chain ID or by individual trust-gate outcome is not documented.

Source: /docs/agents/DASHBOARD.md

confidence high · grounding stated · weight 1.00 · Answered

Protocol plumbing · 81/10013 of 16 checks pass · each fix +6 protocol pts est.

The other half of the score: 16 checks for the files and headers agents look for. The 3 below are installs, not judgment calls, and most are an afternoon. Expand any for the snippet and the standard it follows. They sit after the queue because none of them changes what your pages say.

OpenAPI specInteraction+6 pts est.

StandardOpenAPI SpecIndustry standard

WebMCP widgetInteraction+6 pts est.

Sitedex generates this file from your crawl. Grab it in Files from this audit below.

StandardW3C WebMCP draftW3C / WHATWG

Canonical URLsHygiene+6 pts est.
Install snippet
<link rel="canonical" href="https://valiron.co/" />

StandardRFC 6596IETF RFC

Already passing 13 of 16: robots.txt, sitemap.xml, llms.txt, AI crawler access, Content signal, Clean crawl, Markdown negotiation, Server-rendered content, MCP card, Meta descriptions, HTML lang attribute, Organization schema, Sitemap lastmod.

Ask this site’s index

Sitedex already serves valiron.co as an MCP endpoint. Ask valiron.co anything an AI agent might ask, and see what its index returns. (To score your own site, use the form below.)

Snippets & configs

For developers and the engineer-on-call: copy these into your tools or your site.

Files from this audit

Built from this crawl. Download or copy each, then install it at the path noted.

llms.txt

Built from this crawl. Install at /llms.txt so agents start here.

organization.json

Organization JSON-LD, pre-filled from this crawl. Wrap in a ld+json script.

server-card.json

MCP server card built from this crawl. Host at /.well-known/mcp/server-card.json.

webmcp.json

WebMCP discovery manifest built from this crawl. Host at /.well-known/webmcp.json.

MCP endpoint

https://mcp.sitedex.dev/s/valiron-co/mcp

The URL anyone's agent points at. Read-only; safe to share.

Claude Code

claude mcp add valiron --transport http https://mcp.sitedex.dev/s/valiron-co/mcp

One command, then the agent has it.

Cursor / Continue

{
  "mcpServers": {
    "valiron": {
      "url": "https://mcp.sitedex.dev/s/valiron-co/mcp"
    }
  }
}

Drop into mcp.json.

WebMCP: two parts

WebMCP-capable browsers run the widget at runtime. Crawlers without JS rendering need the discovery manifest to find your tool surface. Install both.

1 · Widget script

<script async src="https://sitedex.dev/widget.js"></script>

Drop in <head>. WebMCP-capable browsers (Chrome 146+ Origin Trial) call navigator.modelContext.provideContext() via this script.

2 · Discovery manifest

{
  "$schema": "https://wellknownmcp.org/schemas/webmcp.json",
  "name": "valiron.co",
  "tools": [
    { "name": "search", "description": "Search valiron.co's indexed content." },
    { "name": "get_page", "description": "Fetch a page from valiron.co as markdown." }
  ]
}

Host alongside the script at /.well-known/webmcp.json. Crawlers that don't render JS rely on this.

Your turn

See which of these questions your site goes silent on.

Free, about 5 minutes. We crawl your site, test it against the buyer questions your category asks, and name what’s vague, contradictory, or missing, plus the files AI agents look for.

ComingEmbeddable grade badgeScore history and deltasOpt-in public board