UK-based cybersecurity firm Valarian has successfully secured $50 million in Series A funding, bringing its total capital raised to $70 million, according to SecurityWeek. This investment highlights an intensifying demand for technology that enables a sovereign infrastructure control layer, allowing organizations to maintain absolute authority over their digital communications, even when utilizing third-party Software-as-a-Service (SaaS) environments.
The Technical Shift Toward Sovereign Infrastructure Control Layer Architecture
As organizations migrate to the cloud, they often sacrifice direct control over data privacy in exchange for the scalability of platforms like Microsoft Teams, Slack, or Zoom. Valarian’s core technology, known as ACRA (Advanced Communications and Resilience Architecture), addresses this by decoupling the application layer from the underlying transport and storage infrastructure. This architecture ensures that sensitive data is encrypted before it leaves the organization’s perimeter, with the keys held exclusively by the customer rather than the platform provider.
This approach aligns with Zero Trust principles, where no entity—including the cloud service provider—is implicitly trusted with the contents of organizational communications. By implementing a sovereign infrastructure control layer architecture, a SOC can maintain rigorous oversight and auditability without exposing plaintext data to external risks or legal subpoenas in foreign jurisdictions. This is particularly relevant for entities targeted by an APT that may attempt to compromise service provider environments to perform Lateral Movement or data exfiltration.
Securing Enterprise Communications on Third-Party Platforms
One of the primary challenges for modern security teams is securing enterprise communications on third-party platforms while maintaining the native user experience. Traditional VPNs or isolated communication silos often fail due to poor adoption or friction. ACRA allows users to continue using familiar tools while the sovereign layer intercepts and secures the data flow at the application level.
From a technical perspective, this prevents the service provider from having visibility into the metadata or the payloads. For organizations operating in defense or critical infrastructure, this level of isolation is necessary to mitigate the impact of a Supply Chain Attack targeting the software vendor. If a provider’s database is breached, the data remains encrypted and useless to the attacker, effectively neutralizing the risk of a massive Data Breach.
Strategic Implications for Regulated Industries
The move toward sovereign control layers is driven by increasing geopolitical tensions and the enforcement of strict data residency laws. When considering how to implement ACRA for data sovereignty, organizations must evaluate their current dependency on global cloud providers. The ability to move data across borders while maintaining local control over the decryption process is a requirement for international compliance in the finance and healthcare sectors.
Furthermore, this technology provides a layer of resilience against platform-wide outages. By controlling the infrastructure layer, organizations can theoretically maintain internal communication channels even if the third-party provider’s central services are compromised or unavailable.
Recommendations for Security Leaders
Security professionals should prioritize the following actions when evaluating sovereign infrastructure solutions:
- Audit Data Exposure: Identify which sensitive internal communications are currently stored in plaintext on third-party cloud servers.
- Evaluate Decoupling Solutions: Assess if tools like ACRA can be integrated without disrupting existing workflows or requiring a complete Migration of communication suites.
- Review Key Management: Ensure that encryption keys are stored in a hardware security module (HSM) or a sovereign vault that is not accessible by the cloud service provider.
- Assess Compliance Requirements: Determine if current cloud usage violates data sovereignty regulations in specific operating regions and if a control layer satisfies these mandates.