Valarian isn't trying to patch the perimeter - it's rebuilding the substrate. Founded in 2020 and headquartered in London, the company builds infrastructure for organisations where compromise isn't an option: government, defence, national security, and enterprise environments where a single lateral movement or credential leak can cascade into operational failure. Their core product, ACRA, transforms Kubernetes into a hardened, governed environment where every workload - agent, model, or service - is wrapped in policy that's defined once and enforced everywhere.
The technical stack reads like a zero-trust reference architecture executed in production. Think SPIFFE/SPIRE for cryptographic workload identity, Cilium and Istio for default-deny network isolation, Kyverno for admission and workload policy enforcement, Vault for short-lived scoped secrets, NATS for per-workload messaging permissions, and end-to-end audit and evidence pipelines. The point isn't tooling for its own sake - it's compartmentalisation at every layer, so that even a compromised component can't move laterally or escalate.
With $70 million in funding and hundreds of enclaves deployed across four continents, Valarian is operating at meaningful scale. The team's pedigree skews toward environments where failure has real consequences: backgrounds from US Special Operations, Palantir, Darktrace, and similar orgs where security and operational reliability aren't aspirational - they're baseline requirements. This isn't a cybersec startup selling dashboards; it's infrastructure for environments where the threat model assumes breach and the architecture must hold anyway.






