valtisec

Barcelona · Security operations · Compliance

We watch your systems so your team can do its job.

Detection, incident response and the evidence NIS2, DORA and ISO 27001 audits ask for. For mid-sized companies, on the tools you already run.

Check your domain's email security

# Free check of your company's email security.
# Reads public DNS only: nameservers, mail servers,
# SPF, DMARC and DNSSEC. Nothing is installed.
# Type your domain below and press Enter.

Services

Three levels. Each one includes the one below.

Scope and price are agreed per client after a scoping call. We work with the SIEM, EDR and cloud platforms you already have; if you have none, we recommend and deploy what fits.

L3Operations

Incident response, threat intelligence, a monthly report, and help with regulatory incident notifications.

Fits ifYou fall under NIS2 or DORA and need detection, response and reporting covered.

L2Detection

Monitoring of endpoints, identity and cloud logs. Detection rules mapped to MITRE ATT&CK, documented and version-controlled. Alerts triaged by our analysts and escalated to your team.

Fits ifNobody in your company watches security alerts today.

L1Exposure

What an attacker sees from outside: domains, email authentication, exposed services and known vulnerabilities. A written report ranked by risk, and a call to go through it.

Fits ifYou want a first view of your risk, or a client has sent you a security questionnaire.

Also on their own: incident response engagements, cloud hardening on AWS, Azure and Google Cloud, and compliance advisory (gap analysis, risk register, supplier assessments, ISMS documentation).

When an alert fires

What happens in the first 72 hours.

Under NIS2 an essential or important entity must send an early warning within 24 hours of becoming aware of a significant incident, and a fuller notification within 72. We run the technical side and draft the reports with you.

 alert --> triage --> contain --> root cause
   |         |           |
   |         +-- false positive: close, tune the rule
   |                     |
   v                     v
 T+0                 T+24h  early warning
                     T+72h  incident notification
                     T+1mo  final report

Regulations

What we help you prove.

NIS2
Art. 21 · Art. 23Risk management measures, and incident reporting at 24 hours, 72 hours and one month.
DORA
Ch. II · Ch. IIIICT risk management, classification and reporting of major ICT-related incidents, resilience testing.
GDPR
Art. 32 · Art. 33Security of processing, and breach notification to the authority within 72 hours.
ISO 27001
2022 · Annex AGap analysis, ISMS documentation and preparation for the certification audit.
Also
on requestNIST CSF 2.0, the Cyber Resilience Act, PCI DSS 4.0 and SOC 2, when your clients or sector require them.

We help you meet these requirements. Valtisec is not a certification body and does not certify compliance.

Contact

Tell us what you need to cover, and by when.

We start with a call about your environment, the rules that apply to you and your deadlines. Then a written scope and price. Work starts once you approve it.

Email
hello (at) valtisec.com
Office
Carrer de Lepant 270, 08013 Barcelona
Languages
English, Spanish
NecessaryStores your cookie choice. Always on.
AnalyticsGoogle Analytics through Google Tag Manager: visits, pages and button clicks.
MarketingHubSpot: links website visits to enquiries in our CRM.

More detail in the cookie policy.

Versión en español. If the two versions differ, the Spanish version prevails.

1. Website owner

Under Article 10 of Spanish Law 34/2002 on Information Society Services (LSSI), valtisec.com is owned by:

2. Purpose

This website describes the cybersecurity, compliance, and detection and response services provided by Valtisec, and lets you contact us or request an assessment.

3. Terms of use

Access is free. You agree to use the site lawfully, not to harm its operation or that of third parties, and to provide accurate information in the forms.

4. Domain check tool

The domain check reads only public DNS records of the domain you enter (such as SPF, DMARC or DNSSEC), from your browser. It does not scan or access any system. You agree to check only domains you own or are authorised to assess. Results are indicative and are not an audit or a security guarantee.

5. Intellectual property

The content, text, design, brand and code of this site belong to D'Carton Digital, S.L.U. or its licensors. Reproduction, distribution or modification without express permission is prohibited.

6. Liability

Content is for information only and is not professional advice for a specific case. We do not guarantee continuous availability of the site and are not liable for damage caused by misuse or by the content of linked third-party sites.

7. Use of artificial intelligence

We use AI tools to support analysis and drafting. An analyst reviews everything we deliver to clients. We do not use client data or data from this website to train third-party models. This site has no chatbot and makes no automated decisions about visitors.

8. Data protection and cookies

Personal data is handled under our privacy policy, and cookies under our cookie policy.

9. Governing law

These terms are governed by Spanish law. Disputes are submitted to the courts of Barcelona, unless the applicable law sets a different venue.

Last updated: 1 October 2026.

Privacy policy

Versión en español. If the two versions differ, the Spanish version prevails.

1. Controller

D'Carton Digital, S.L.U. (Valtisec), CIF B25910985, Carrer de Lepant 270, Entresuelo, 08013 Barcelona, Spain. Data protection contact: hello (at) valtisec.com.

2. Data we process

Fields marked as required are needed to answer you. Without them we cannot reply.

Domain check: runs in your browser when you ask for it (Article 6.1.b GDPR). Your browser sends the domain and your IP address to Google LLC (dns.google), which acts as an independent controller under its own privacy policy and may process them in the United States. We do not store the domain unless you request the review.

3. Purposes and legal basis

We do not make automated decisions or build profiles that have legal effects on you.

4. Retention

Enquiries that do not lead to a business relationship are kept for up to 12 months. For clients, data is kept for the duration of the relationship and then for the legal periods that apply (for example, 6 years for commercial records). Cookie data is kept for the periods in the cookie policy.

5. Recipients

We do not sell or share your data, except where the law requires it. The following providers process it on our behalf, under a contract that meets Article 28 GDPR:

6. International transfers

Cloudflare, Inc., Google LLC and HubSpot, Inc. may process data in the United States under the EU-US Data Privacy Framework and/or the European Commission's standard contractual clauses. You can ask us for a copy of the safeguards at hello (at) valtisec.com.

7. Your rights

You can request access, rectification, erasure, objection, restriction and portability, and withdraw consent at any time, by emailing hello (at) valtisec.com with the subject "Data protection". If you think we have not handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es).

8. Security

We apply technical and organisational measures suited to the risk to protect your data against unauthorised access, loss or alteration.

Last updated: 1 October 2026.

Versión en español. If the two versions differ, the Spanish version prevails.

1. What they are

Cookies and similar technologies (such as your browser's local storage) are files a website stores on your device to remember information about your visit.

2. Cookies we use

Analytics and marketing cookies are not set until you accept them. Google Tag Manager, which manages them, does not load without your consent either.

NameProviderPurposeDurationType
valtisec_consent_v2Valtisec (local storage)Remember your cookie choice12 monthsTechnical (no consent needed)
_ga, _ga_*Google AnalyticsTell visitors apart and produce usage statistics2 yearsAnalytics
__hstc, hubspotutkHubSpotIdentify visits and link them to enquiries in the CRM6 monthsMarketing
__hsscHubSpotCount pages viewed in the session30 minutesMarketing
__hssrcHubSpotDetect a browser restartSessionMarketing

3. Third-party resources without cookies

Fonts are served by Bunny Fonts (BunnyWay d.o.o., Slovenia, EU), which receives your IP address to deliver them, sets no cookies and states that it does not log IP addresses. The domain check queries Google's public DNS resolver only when you use it. When you start filling in a form, Cloudflare Turnstile loads to check that you are not a bot; it is necessary for the form to work and does not use cookies for advertising or tracking. These services receive your IP address to answer the request.

4. Changing or withdrawing consent

You can change your choice at any time from , also in the footer. When you withdraw consent we delete the analytics and marketing cookies for this domain. You can also block or delete cookies in your browser settings.

For more on how we handle your data, see the privacy policy.

Last updated: 1 October 2026.

English version

1. Titular del sitio web

En cumplimiento del artículo 10 de la Ley 34/2002, de Servicios de la Sociedad de la Información y de Comercio Electrónico (LSSI), se informa de que el sitio web valtisec.com es titularidad de:

2. Objeto

Este sitio web ofrece información sobre los servicios de ciberseguridad, cumplimiento normativo y detección y respuesta prestados por Valtisec, y permite contactar con nosotros o solicitar una evaluación.

3. Condiciones de uso

El acceso al sitio web es gratuito y atribuye la condición de usuario. El usuario se compromete a utilizar el sitio de forma lícita, sin dañar su funcionamiento ni el de terceros, y a facilitar datos veraces en los formularios.

4. Herramienta de comprobación de dominio

La comprobación de dominio consulta únicamente registros DNS públicos del dominio indicado (como SPF, DMARC o DNSSEC) desde el navegador del usuario. No realiza escaneos ni accede a sistemas. El usuario se compromete a comprobar solo dominios propios o sobre los que disponga de autorización. Los resultados son orientativos y no constituyen una auditoría ni una garantía de seguridad.

5. Propiedad intelectual e industrial

Los contenidos, textos, diseño, marca y código del sitio web pertenecen a D'Carton Digital, S.L.U. o a sus licenciantes. Queda prohibida su reproducción, distribución o transformación sin autorización expresa.

6. Responsabilidad

Los contenidos tienen carácter informativo y no constituyen asesoramiento profesional para un caso concreto. D'Carton Digital, S.L.U. no garantiza la disponibilidad continua del sitio y no responde de los daños derivados de un uso indebido del mismo ni del contenido de sitios de terceros enlazados.

7. Uso de inteligencia artificial

Usamos herramientas de IA como apoyo en tareas de análisis y redacción. Un analista revisa todo lo que entregamos a clientes. No usamos datos de clientes ni de este sitio web para entrenar modelos de terceros. Este sitio no tiene chatbot ni toma decisiones automatizadas sobre los visitantes.

8. Protección de datos y cookies

El tratamiento de datos personales se rige por la política de privacidad y el uso de cookies por la política de cookies.

9. Legislación aplicable y jurisdicción

Estas condiciones se rigen por la legislación española. Para cualquier controversia, las partes se someten a los juzgados y tribunales de Barcelona, salvo que la normativa aplicable establezca otro fuero.

Última actualización: 1 de octubre de 2026.

Política de privacidad

English version

1. Responsable del tratamiento

D'Carton Digital, S.L.U. (Valtisec), CIF B25910985, con domicilio en Carrer de Lepant 270, Entresuelo, 08013 Barcelona (España). Contacto para protección de datos: hello (at) valtisec.com.

2. Datos que tratamos

Los campos marcados como obligatorios son necesarios para atender tu solicitud; sin ellos no podremos responderte.

Comprobación de dominio: se realiza en tu navegador a petición tuya (art. 6.1.b RGPD). Tu navegador envía el dominio y tu dirección IP a Google LLC (dns.google), que actúa como responsable independiente conforme a su política de privacidad y puede tratarlos en EE. UU. No almacenamos el dominio salvo que solicites la evaluación.

3. Finalidades y base jurídica

No tomamos decisiones automatizadas ni elaboramos perfiles con efectos jurídicos sobre ti.

4. Plazo de conservación

Las consultas que no den lugar a una relación comercial se conservan un máximo de 12 meses. Si pasas a ser cliente, los datos se conservan mientras dure la relación y, después, durante los plazos legales aplicables (por ejemplo, 6 años para la documentación mercantil). Los datos de cookies se conservan durante los plazos indicados en la política de cookies.

5. Destinatarios

No vendemos ni cedemos tus datos a terceros, salvo obligación legal. Tienen acceso a ellos, como encargados del tratamiento y con contrato conforme al art. 28 RGPD, los proveedores necesarios para prestar el servicio:

6. Transferencias internacionales

Cloudflare, Inc., Google LLC y HubSpot, Inc. pueden tratar datos en EE. UU. al amparo del Marco de Privacidad de Datos UE-EE. UU. y/o de las cláusulas contractuales tipo de la Comisión Europea. Puedes solicitar copia de las garantías en hello (at) valtisec.com.

7. Tus derechos

Puedes ejercer los derechos de acceso, rectificación, supresión, oposición, limitación del tratamiento y portabilidad, así como retirar tu consentimiento en cualquier momento, escribiendo a hello (at) valtisec.com con el asunto "Protección de datos". Si consideras que no hemos atendido correctamente tu solicitud, puedes presentar una reclamación ante la Agencia Española de Protección de Datos (www.aepd.es).

8. Seguridad

Aplicamos medidas técnicas y organizativas adecuadas al riesgo para proteger tus datos frente a accesos no autorizados, pérdida o alteración.

Última actualización: 1 de octubre de 2026.

Política de cookies

English version

1. Qué son

Las cookies y tecnologías similares (como el almacenamiento local del navegador) son archivos que un sitio web guarda en tu dispositivo para recordar información sobre tu visita.

2. Cookies que utilizamos

Las cookies de analítica y marketing no se instalan hasta que las aceptas. Google Tag Manager, la herramienta que las gestiona, tampoco se carga sin tu consentimiento.

NombreProveedorFinalidadDuraciónTipo
valtisec_consent_v2Valtisec (almacenamiento local)Guardar tu elección sobre cookies12 mesesTécnica (exenta de consentimiento)
_ga, _ga_*Google AnalyticsDistinguir visitantes y obtener estadísticas de uso2 añosAnalítica
__hstc, hubspotutkHubSpotIdentificar visitas y vincularlas a consultas en el CRM6 mesesMarketing
__hsscHubSpotContar las páginas vistas en la sesión30 minutosMarketing
__hssrcHubSpotDetectar el reinicio del navegadorSesiónMarketing

3. Recursos de terceros sin cookies

Las tipografías se sirven desde Bunny Fonts (BunnyWay d.o.o., Eslovenia, UE), que recibe tu dirección IP para entregarlas, no instala cookies y declara no registrar direcciones IP. La comprobación de dominio consulta el resolvedor DNS público de Google solo cuando la usas. Cuando empiezas a rellenar un formulario se carga Cloudflare Turnstile, que comprueba que no eres un bot; es necesario para que el formulario funcione y no usa cookies publicitarias ni de seguimiento. Estos servicios reciben tu dirección IP para responder a la petición.

4. Cómo gestionar o retirar tu consentimiento

Puedes cambiar tu elección en cualquier momento desde o desde "Cookie settings" en el pie de página. Al retirar el consentimiento eliminamos las cookies de analítica y marketing de este dominio. También puedes bloquear o borrar cookies desde la configuración de tu navegador.

Para más información sobre el tratamiento de tus datos, consulta la política de privacidad.

Última actualización: 1 de octubre de 2026.