Security & Trust
An AI with the keys to your IT. Guarded accordingly.
Resolv holds your staff conversations, your runbooks, and credentials into your systems. Here is exactly how we keep them safe, who can touch them, and what we would hand your auditor if you asked.
SOC 2
designed to controls
ISO 27001
alignment in progress
UAE PDPL
Federal Decree-Law No. 45
NESA / UAE IA
government roadmap
01 · Pillars
Six principles, no exceptions.
Resolv’s security posture comes back to six ideas. Every product decision passes through them; every engineer onboards on them.
Pillar 01
Tenant isolation, enforced twice
Company A cannot see Company B — enforced in the application and again at the database. Not a setting. Architecture.
- Every query scoped to your company
- Row-Level Security forced at the database
- Cross-tenant isolation tested in CI on every merge
- Privileged code paths explicitly re-scoped
- Per-company config, credentials and spend caps
Pillar 02
Encrypt everything
Data is encrypted in transit and at rest. The credentials that reach into your systems get their own layer.
- TLS 1.2+ end-to-end
- Encryption at rest across the platform
- AES-256-GCM envelope encryption for integration credentials
- Secrets never in code, never in logs
- Constant-time comparison for tokens and secrets
Pillar 03
Least privilege, always
Access follows the role, not the person. Privileged access is gated, logged and reviewable.
- Role-based access: admin, agent, operator
- Auth checked first on every route and action
- SSO for enterprise deployments
- Operator console gated behind a separate secret
- Every privileged action lands in the audit trail
Pillar 04
The AI is under control
The part most vendors hand-wave. Resolv treats its own AI as a principal to be governed, not trusted.
- Policy engine decides what agents may do unaided
- Sensitive actions queue for one-click human approval
- Reasoning loops hard-capped; low confidence escalates
- Structured, typed outputs — never free-form execution
- Prompt-injection defence and PII redaction in logs
Pillar 05
Data stays where you need it
Residency is a deployment decision you make, not a promise we make. Up to and including your own perimeter.
- UAE / regional data-residency options
- Regional model routing for regulated industries
- On-premise sovereign deployment for government
- Your knowledge base is never shared across tenants
- Customer-initiated export and deletion
Pillar 06
Auditable by you, not us
Every state change writes a permanent record. The log is append-only — the database refuses edits and deletes.
- Append-only audit trail, enforced at the database
- Who, what, when, before and after — plus request ID
- Every AI action attributed and reviewable
- Exportable for your auditors
- Written post-mortem after any incident
02 · Architecture
How a request is handled.
From a staff message to an action in your systems, six layers stand between an attacker and your environment.
Defence in depth
Each layer is independently logged and monitored. Compromise one and the next still stands.
03 · Certifications
Where we stand.
We are building toward formal certification and will not claim what has not been audited. Here is the honest status of each, and what we can share under NDA today.
SOC 2 Type II
We build to the Trust-services criteria across Security, Availability and Confidentiality, working toward a Type II audit.
ISO/IEC 27001:2022
Our information security management system is being built to align with ISO 27001, scoped to all Resolv production systems.
UAE PDPL
We design to Federal Decree-Law No. 45 of 2021, including residency and processing controls, ahead of an independent gap analysis.
NESA / UAE IA
Government deployments are designed against the UAE Information Assurance standard; alignment work is scoped per engagement.
04 · Subprocessors
Who else touches your data.
The vendors we rely on in the managed cloud edition, each bound by a data-processing agreement. We update this page before adding anything new.
| Subprocessor | Purpose | Data handled |
|---|---|---|
| AWS · EKS + CloudFrontAmazon Web Services | Compute, hosting and edge delivery | Application traffic · UAE (me-central-1) |
| AWS · Aurora PostgreSQLAmazon Web Services | Database and vector search | Tenant data · UAE (me-central-1) |
| AWS · S3, KMS & CognitoAmazon Web Services | Storage, encryption keys and identity | Documents, keys and logins · UAE region |
| AnthropicAnthropic PBC | AI inference (primary model) | Conversation content · no training |
| OpenAIOpenAI LLC | AI inference + text embeddings | Conversation and document text · no training |
| GoogleGoogle LLC | AI inference (Gemini) | Conversation content · no training |
| StripeStripe Payments | Subscription billing | Billing details only |
| AWS · SESAmazon Web Services | Transactional email | Email addresses only · UAE region |
| SentryFunctional Software Inc. | Error monitoring | Scrubbed metadata only |
Government and regulated deployments can run the Ops Platform Edition entirely inside your perimeter — with no external subprocessors at all.
05 · Vulnerability program
Tell us if you find something.
Responsible disclosure + third-party pen test
We run a responsible-disclosure programme and commission independent penetration testing. Researchers acting in good faith are covered by our safe-harbour policy.
Report any vulnerability to security@resolv.so.
Critical target
48 hrs
patched and deployed
High target
7 days
patched and deployed
Triage target
1 day
first response to a report
Pen test
Independent
summary shared under NDA
Our commitment — transparency by default
06 · For auditors & legal
Documents, in one place.
LEGAL
Data Processing Addendum
PDPL-aligned processing terms and transfer mechanism. Counter-signature within 48 hours.
COMPLIANCE
SOC 2 readiness summary
Where we are on the path to a Type II audit, and the controls already in place.
ARCHITECTURE
Isolation test evidence
The cross-tenant isolation suite that runs in CI — what it asserts, and its latest results.
ARCHITECTURE
Network & data-flow narrative
Production architecture and the per-request data-flow narrative for your security review.
AI GOVERNANCE
AI safety & evaluation summary
Policy gates, approval flows, evaluation datasets and red-team methodology.
LEGAL
Privacy policy
Built to PDPL. A plain-English breakdown of every category of data we hold.
Talk to us about security
Get the architecture walkthrough and our security documentation in a 30-minute call.
Live in days · Nothing to install · Every action audited