Case projections for organisations. In batches, across borders.

One call carries up to two hundred cases, each under its own assumptions and discounted by the country the person actually lives in. Nobody is named to us: your reference goes in, your figure comes out.

Move the figures Read the API

Status · early access, no charge

It is open to firms and there is no charge for it. No price is quoted anywhere, nothing is invoiced, and no payment method is taken. A firm asks by writing to us, and an account is created by invitation rather than by signing up; the terms, the privacy notice and the processing agreement are published, and no lawyer has reviewed them — each of them says so. What is still missing is listed further down, and if this is the shape of thing you need, write to contact@valnivo.eu.


200cases in one call
10plans per case
37countries of residence
0client names held

The screens

Four screens, and a book only your firm can read

A book of clients, one client’s figures with the questions a firm actually asks beside them, and the firm itself — who is in it and what each of them may do. These are illustrations, drawn rather than photographed, and every reference on them begins DEMO- so that none can be mistaken for a real book.

The book

Every client, as a reference

A firm’s whole book on one screen — each client a reference of your own, a country and a set of figures. There is no field for a name anywhere on it, because a client’s identity stays in your system and never reaches ours.

A client

The plans, side by side

What each plan comes to at the horizon and in today’s prices, discounted by that client’s own country’s inflation. The panels are the same calculators the consumer app uses, seeded from this client, arranged the way your firm wants them.

The firm

Who is in it, and what each may do

Running the firm and seeing what it plans for are separate powers, not a ladder — so an administrator manages seats and keys and does not read a client by doing so. The database refuses it too, not just the screen.

The handover

Something to give the client

A document written here and stored nowhere, carrying the clause on every page because a page handed over alone is the page somebody reads. A request that carries a name is refused rather than rendered with a warning.

Ask to be enrolled

Move the figures

Watch the answer move. Same engine as the API.

Four quantities and a country, and the number beside them comes out of the same function the endpoint answers from — not a mock-up with plausible figures in it. Nothing is sent anywhere and there is nothing here to type a name into, which is the boundary this page spends a whole section on and does not suspend for its own demonstration.

The API

One call, up to 200 cases, up to 10 plans each

Your system sends references and figures. Ours sends figures back. The same request works for one client and for a whole book, and the API refuses anything that looks like a name. Every figure is an integer in minor units in both directions, and one bad case comes back in rejected with its reference rather than failing the batch.

200Answered — with any case we could not take in rejected, its own reference beside it.
400No cases array, or an empty one — the request is not a batch.
413More than 200 cases in one request. More than 10 plans is that case rejected, not the batch.
401No key, or one that has expired or been withdrawn — and the answer says which.
503Case batches are not switched on for this deployment yet. The calculation endpoints still answer.
POST /v1/cases/projections
{
  "cases": [
    {
      "ref": "A-1042",            // your reference. never a name
      "country": "LU",
      "currency": "EUR",
      "starting": 1000000,        // minor units: €10,000.00
      "monthly": 50000,
      "plans": [
        { "ref": "as things are", "years": 20, "returnRate": 0.05 },
        { "ref": "€300 more",     "years": 20, "returnRate": 0.05,
          "monthly": 80000 }
      ]
    }
  ]
}
{
  "counted": 1,
  "results": [
    {
      "ref": "A-1042",
      "currency": "EUR",
      "plans": [
        {
          "ref": "as things are",
          "years": 20,
          "nominal": 22943522,
          "inTodaysPrices": 15140675,
          "contributions": 13000000,
          "growth": 9943522,
          "inflationUsed": 0.021
        },
        { "ref": "€300 more", "years": 20,
          "nominal": 35117657, "inTodaysPrices": 23174517,
          "contributions": 20200000, "growth": 14917657,
          "inflationUsed": 0.021 }
      ]
    }
  ],
  "rejected": [],
  "disclaimer": "Illustrations built on the assumptions in
                 this request. Not a forecast, not advice…"
}
// 200 — the batch is answered, this case is not
{
  "counted": 0,
  "results": [],
  "rejected": [
    {
      "ref": "A-1042",
      "error": "Remove \"email\": a case carries figures
                and your own reference, never anything
                identifying a person."
    }
  ]
}

Roles

You are the controller. We are the processor.

  1. 01

    You decide the figures, we do the arithmetic

    The figures are yours, collected from your own clients under your own basis. Your people enter the assumptions and the references; the engine applies the rules and hands the figures back, and nothing is inferred or stored on our side. The processing agreement is accepted when your firm claims its account, so it is in place before any real data moves.

  2. 02

    The people behind the figures are yours

    A reference is meaningful only in your system. To ours it is a label on a set of numbers, so their identities never leave your control. They never meet us and have no account with us: telling them their data is processed is your duty under art. 14, and what we do is keep our side small enough that it stays easy.

  3. 03

    The processing agreement makes it binding

    The API stores no case you send it — it is arithmetic on the request, answered and forgotten. A client you enter in the application is different, and this says so plainly: it is stored, in the EEA, in a scope sealed with a key your own people hold. Its figures are ciphertext to us and the only thing in the clear is the reference you chose, which is why that reference must never be a name. Valnivo holds no key and keeps no escrow, so we cannot read a client of yours and cannot recover one for you either. For that storage we are your processor under art. 28, and the agreement is accepted when your firm claims its account.

Boundary

What keeps this a calculation rather than a regulated activity

These are not features waiting to be prioritised. It is the same boundary the consumer app lives inside.

Never say what a person can afford, borrow or should do.

Modelling a plan the firm chose is arithmetic; assessing a person is not, and a creditworthiness judgement is a lender’s own regulated duty.

Never name, rank or compare a fund, account, provider or policy.

That is investment advice or intermediation, whoever asks for it.

Never connect to a bank.

Fetching accounts or balances is an account information service under PSD2, needing authorisation or a licensed aggregator.

Never take a referral fee.

Commission for sending somebody to a broker or insurer makes the tool an intermediary regardless of wording.

Every figure the API returns carries a sentence with it saying it is an illustration built on the assumptions in the request, and not a forecast or advice. A case batch carries the whole clause: not a forecast, not advice, and not a statement of what anyone can afford or should do.

Where it stands

Where each piece stands, listed rather than implied

Open one to read what is behind it. The application is open to firms; the API is the part still waiting, and this says on what.

Issued to
An organisation, never a person
Checked
At the edge, before any arithmetic runs
Revocable
Per key, by you or by us
Before it
The processing agreement, accepted when the firm claims its account
A party to contract with Answered

22 September 2026, reworded 28 September. There is a party and it is named by its trade name, Valnivo Labs, of Luxembourg. Valnivo Labs is a trade name, not a registered company. The name of the person responsible is given on request and without condition for a formal data-protection request or a complaint to a supervisory authority. That is weaker than the law wants — every published document says so rather than hiding it. Nothing is invoiced, so the second half of this, a party to issue an invoice, is not yet needed.

Somewhere to run it Done

Done, 18 September 2026: it runs on Google Cloud Run, in a project of its own, closed to everybody — a request without our own credentials is refused before the service sees it. What is still missing is not the machine.

Keys that mean something Built, not switched on

Written 19 September 2026, and not yet in force. A key is a signed token naming your organisation, its scope and an expiry, verified with a public key — so the service can check a key and cannot mint one, and a leaked configuration is not a key factory. We would keep a hash and never the key, and you could see what you hold and withdraw it yourself. What is missing is the verifying key itself: the deployed configuration carries an empty one, so nothing has been issued to anybody and no key has ever been checked in anger. It is one value and a first customer away, and until then this reads as built rather than done.

Terms, a privacy notice and the processing agreement Published

Published 22 September 2026; version 2 on 30 September: terms of use, privacy notice and processing agreement, each generated from one source so a served clause and our own record cannot differ. Version 2 describes what the application stores — each client a firm enters, sealed — where version 1 described computation alone. The art. 28 agreement is executed by acceptance when a firm claims its account, and the version accepted is recorded against the firm — that duty attaches to processing rather than to payment, so it is in force from the first client a firm enters even though nothing is charged. No lawyer has reviewed them, and each of them says so.

Rate limits, an audit trail and an exit plan Done

19 September 2026, completed 22 September: requests are limited per caller, and there is an append-only trail of who opened what — a member, a scope, an action and a time, never a figure. The limit is per instance and says so, which is what a limiter without shared state can honestly claim. The exit plan was waiting on the contract and is now clause 8 of the processing agreement: what is returned or deleted at the end, and when.

Plan for peopleyou never have to name to us.

Talk to Valnivo Read the API →