RESOLV

Trust center

Built to use your data securely, without compromising privacy.

A security firm is judged first by how it protects itself. This page sets out what we do today, and what we will not claim until it is independently verified.

This website

Controls you can check for yourself.

Every control below can be verified with your browser’s developer tools or a public header scanner.

Strict content security policy

A unique cryptographic nonce on every request. No inline or third-party scripts can run.

Encrypted transport

HTTPS enforced with HSTS, so browsers never connect over plain HTTP.

Hardened headers

Framing by other sites is blocked, content sniffing is disabled and powerful browser features are switched off.

No tracking

No advertising cookies, analytics profiling or third-party trackers. The only cookie stores your theme.

Self-hosted fonts

Your visit is not shared with a font provider or content network for typography.

Enquiries never logged

Contact-form submissions are validated on the server and are never written to application logs.

Client engagements

How we handle your data and systems.

Least-privilege access
Access to client systems is granted per engagement, only to the people doing the work, and removed at handover.
Separation between clients
Each client’s data, credentials and environments are kept separate from every other client’s.
Your data, your purpose
Client data is used only to deliver the engagement, never for any other purpose, and is returned or deleted when it ends.
Written agreements
Confidentiality and data-processing terms are agreed in writing before any personal data is handled.

Secure development

Security is built in, not bolted on.

  1. 01

    Threat model first

    Risks are identified at design time, not after build.

  2. 02

    Tests before code

    Tests are written to fail before the fix, then proved to pass.

  3. 03

    Review every change

    Nothing merges without review, and risky changes get adversarial review.

  4. 04

    Scan continuously

    Dependencies and secrets are scanned on every change.

  5. 05

    Test before release

    Security testing evidence is produced before anything ships.

Read our full delivery standard →

Compliance posture

We design our controls around recognised frameworks, including ISO/IEC 27001, the NIST Cybersecurity Framework and the OWASP Application Security Verification Standard. We do not currently hold a formal certification, and we will not display one until it has been independently audited and awarded.

If something goes wrong

If we become aware of a security incident affecting client data, we contain it, investigate it and notify the affected client without undue delay, with the facts we have and the steps we are taking, in line with our contracts and the law.

Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers. Report a suspected vulnerability in a Resolv system through our contact page, with enough detail for us to reproduce it.

  • We will acknowledge your report and keep you informed as we investigate.
  • We will not take legal action against good-faith research that follows this policy.
  • Please do not access, change or delete data that is not yours, degrade our services, or disclose the issue publicly until it is fixed.
  • Systems we operate for clients are out of scope unless the client has authorised testing.

Have a security question?

Procurement and security teams can request further detail on any control. A senior engineer replies within one business day.