trust center

Security, engineered into every system

our principles

Security is part of how we engineer trust

At Resolute,security is not a final checkpoint.It is built into how we modernize legacy systems, reduce technology debt, and deploy AI in environments where reliability and accountability matter.

Security is designed in

Built into architecture and delivery from day one

Modernization reduces risk

We remove technology and security debt, not relocate it

AI respects data boundaries

AI solutions are deployed with agreed data boundaries, controlled access, and privacy-aligned model selection

Least privilege by default

Access is controlled, intentional, and auditable

Shared responsibility is explicit

We secure what we build; clients control their environment

Transparency over guarantees

No “zero risk” claims; clear processes and accountability instead

Read Resolute’s full security manifesto

Read more

Certifications

Certifications are maintained through regular audits and continuous improvement processes.

ISO 9001:2015

Quality Management

2025

ISO/IEC 27001:2022

Information Security Management

2025

ISO/IEC 20000-1:2018

IT - Service Management

2025

External validation

EcoVadis Commitment

2025

How we build and operate secure systems

Secure engineering & delivery

  • Secure SDLC embedded in delivery

  • Vulnerability management (triage → fix → verify)

  • Secure coding and peer review practices

  • Dependency and third-party package review

  • Separation between development and production environments

  • Controlled access to source repositories and CI/CD pipelines

  • Modernization that reduces security and technology debt

AI & data responsibility

  • Clear data boundaries (RAG, scoped inputs)

  • AI solutions operate within client-approved environments and access boundaries

  • No training on client data unless explicitly agreed and contractually authorized

  • Source-aware, traceable outputs

  • Controlled environments (tenant isolation where required)

  • Human-in-the-loop for critical decisions

Operations, reliability & response 

  • Monitoring and system observability

  • Structured incident response process

  • Clear client communication for material incidents

  • Change management to prevent regressions

  • Managed services controls (monitoring, patching, logging, anomaly detection)

Access, data & privacy

  • Role-based access and least privilege

  • Encryption in transit and at rest (where applicable)

  • Data minimization by design

  • Client data ownership and control

  • GDPR-aligned data processing

shared responsibility

Security responsibilities in cloud, AI, and custom software engagements are shared between Resolute and the client.

We are responsible for the systems we design and deliver within scope. Clients remain responsible for the controls within their environment.

Resolute Client
AI systems Prompting, RAG architecture, integration  Tenant, infrastructure, API keys
Data access Enforcing access logic in systems IAM policies, data provisioning
Application security Secure development, vulnerability fixes Infrastructure monitoring, OS patching
Outcomes Delivered working system Validation, human oversight

Extended cybersecurity expertise, supported by Amatas

Resolute works closely with Amatas, a cybersecurity company within the Ocean Investments group, to extend our capabilities across security operations, testing, and governance.

What this means for our clients:

  • Access to dedicated cybersecurity expertise

  • Security testing and independent validation

  • Monitoring and incident response capabilities where required

Together, we ensure systems are not only built securely but remain secure over time.

Security documentation & assurance

Public

  • Security overview

Available on request

  • ISMS overview

  • Secure SDLC overview

  • Standard security questionnaire

Request security documentation

Vulnerability reporting

If you believe you have identified a security vulnerability related to Resolute systems or services, please report it through our designated security channel.

Reported issues are reviewed, assessed, and addressed through established internal processes.

Report a vulnerability

Frequently askes questions

No. Client data is not used for AI model training unless explicitly agreed in writing and approved by the client. AI solutions operate within defined, client-approved data and access boundaries.

AI solutions can be deployed in client-controlled cloud environments or agreed managed environments, depending on the engagement model. Deployment architecture, hosting, and data access boundaries are defined during solution design.

Yes. Resolute regularly works within client-managed Azure, AWS, and hybrid enterprise environments. Access, deployment, and operational responsibilities are aligned during onboarding and delivery planning.

Additional security and compliance documentation can be shared as part of vendor due diligence and onboarding processes.

Security concerns or suspected vulnerabilities can be reported through our designated security contact channel.

Reported issues are reviewed, triaged, and addressed through defined internal processes.

Access is granted based on least privilege principles and aligned with project responsibilities. Sensitive access is controlled, reviewed, and limited to authorized personnel where applicable.

Yes. Resolute supports enterprise delivery requirements through established engineering, security, and operational practices. This includes secure development processes, controlled access, auditability, and alignment with applicable client requirements.

Security responsibilities are shared between Resolute and the client, depending on the delivery and hosting model. Specific responsibilities are clarified during scoping, architecture, and onboarding activities.

Want to learn more about Resolute’s security practices?

Contact our team

Connection lost. Reconnecting...