RESOLV

Industries · Government

Digital public services citizens can trust.

Ministries and agencies hold the most sensitive records a nation has. We build and protect the systems that serve citizens, with the controls an auditor expects.

Sector context

The landscape.

Ministries, agencies and local authorities are custodians of records that citizens cannot opt out of: identity, land, tax, civil status and benefits. When those systems fail or leak, the consequence is not lost revenue but lost public trust, and that is slow to rebuild.

Most public bodies run a mix of paper processes, ageing line-of-business systems and newer digital services built under separate procurements. Integration is often manual, audit trails are incomplete, and the knowledge needed to operate each system sits with a small number of people or an outside vendor.

Modernisation therefore has to be incremental, evidenced and reversible. Services must keep running during the change, every access to a sensitive record must be attributable, and the civil service must be able to operate what is delivered once the contract ends.

Risks

What keeps leaders up at night.

01

Unattributable access to records

Shared accounts and missing audit logs make it impossible to show who viewed or changed a citizen record, which undermines both investigations and public accountability.

02

Vendor lock-in

Systems delivered without source code, documentation or runbooks leave the authority dependent on a single supplier for every change and every incident.

03

Uneven connectivity

Services designed for a fast, stable network fail at regional offices and service points where connectivity is intermittent.

04

Big-bang migrations

Replacing a registry in one cut-over risks data loss and service interruption with no practical route back.

05

Reporting obligations

Donor-funded and publicly procured programmes carry delivery and financial reporting duties that ad hoc project tracking cannot satisfy.

Regulation & standards

The rules we design for.

Data-protection law
Lawful basis, purpose limitation, minimisation and subject rights designed into each service, with records of processing maintained.
ISO/IEC 27001
An information security management system with risk treatment and controls appropriate to sensitive public records.
ISO 15489
Records-management principles for capture, retention, disposition and the evidential integrity of official records.
WCAG 2.2
Accessibility of citizen-facing services, so that public services are usable by everyone they are meant to serve.

Typical engagements

What working together looks like.

Registry modernisation

Replacing a paper or legacy registry with a digital system, migrated in stages with the old system available until the new one is proven.

  1. 01Map the current process, data model and every system that reads from or writes to the registry
  2. 02Design the target data model, access roles and audit requirements with the records owner
  3. 03Build the new registry with full audit logging and role-based access from the first release
  4. 04Migrate records in batches, reconciling each batch against the source before cut-over
  5. 05Run old and new in parallel for a defined period, then retire the legacy system
  6. 06Train the operating team and hand over documentation, runbooks and source code

Citizen service portal

A single, accessible front door to a set of public services, built to work on mobile devices and limited networks.

  1. 01Research how citizens currently access the service, including in person and through intermediaries
  2. 02Prioritise the services with the highest volume and the clearest rules
  3. 03Design accessible, multilingual journeys and test them with real users
  4. 04Integrate with back-office systems through documented, monitored interfaces
  5. 05Security-test before launch and publish the service with defined service levels

Security and resilience review

An independent assessment of the controls protecting sensitive public systems, with a prioritised remediation plan.

  1. 01Agree scope, rules of engagement and the systems in and out of scope
  2. 02Test applications, networks and identity controls
  3. 03Review backup, recovery and incident-response arrangements against stated objectives
  4. 04Deliver a risk register and remediation plan written for leadership and technical teams
  5. 05Retest remediated findings and confirm closure

Working in government?

A senior engineer reviews every enquiry and replies within one business day.