Purpose and scope
The policy applies to ResoluteX personnel, contractors, systems, devices, repositories, and third parties that handle information for company operations or customer delivery.
Its objective is to preserve confidentiality, integrity, and availability without claiming that every customer system has the same risk profile or control set.
Information ownership and classification
Information is handled according to its owner, sensitivity, contractual restrictions, and legal obligations. Customer information remains customer information; access does not transfer ownership.
- Public: approved for public distribution.
- Internal: limited to ResoluteX operations and authorised collaborators.
- Confidential: customer, commercial, personal, or security information requiring controlled access.
- Restricted: credentials, regulated records, production secrets, and other information requiring the strongest practical controls.
Access and identity
Access is granted for a defined purpose, limited to the minimum practical permissions, and reviewed when responsibilities change. Customer-controlled identities and repositories are preferred wherever the delivery model permits them.
- Individual accounts rather than shared credentials.
- Multi-factor authentication for systems that support it.
- Secrets kept out of source code and shared only through approved channels.
- Access removed at handover, role change, or the end of an engagement.
Secure delivery
Security work is proportional to the system being built. A public marketing site and a healthcare workflow do not receive the same threat model, evidence, or release controls.
- Customer code is kept in agreed repositories with traceable changes.
- Dependencies and open-source licences are reviewed as part of delivery.
- Relevant functional, security, accessibility, and release checks are recorded.
- Production changes, backups, logging, and recovery responsibilities are assigned before launch.
Data protection and residency
ResoluteX seeks to collect and retain only the information required for the stated purpose. Customer-hosted work follows the region and controls selected by the customer. Managed products follow their product terms and any signed processing agreement.
Encryption, retention, deletion, backup, and export requirements are documented for the actual deployment rather than implied by a company-wide marketing claim.
Suppliers and subprocessors
Third parties are selected for a defined role and receive only the information needed for that role. Material infrastructure, model, communication, or delivery providers are disclosed where the engagement or applicable law requires it.
Specialist partners remain accountable for regulated services such as employment, legal, tax, payroll, or insurance work; ResoluteX does not relabel their responsibilities as its own.
Incidents and continuity
Suspected security events are triaged, contained, investigated, and documented. Notification obligations and response contacts follow the affected contract and applicable law.
Recovery planning is based on the service boundary: the owner of backups, restore testing, infrastructure, and customer communication must be named before production use.
People, review, and reporting
Personnel are expected to protect credentials, report suspicious activity, follow customer security requirements, and avoid moving customer information into unapproved tools. This policy is reviewed when material technology, legal, or operating changes make an update necessary.
Report a vulnerability or security concern to engineering@resolutexhq.com. Please do not include production credentials or sensitive personal data in the first email.
Related policies

