Skip to content

Information security policy

Security is a delivery boundary, not a badge.

This policy describes the baseline used to protect ResoluteX systems, customer information, and delivery environments. Engagement-specific controls are documented in the signed scope, security schedule, or data-processing agreement.

Last updated

30 July 2026

ResoluteX does not present this page as an ISO certification or third-party assurance report. It is a public statement of the controls we expect our people and delivery partners to follow.

01

Purpose and scope

The policy applies to ResoluteX personnel, contractors, systems, devices, repositories, and third parties that handle information for company operations or customer delivery.

Its objective is to preserve confidentiality, integrity, and availability without claiming that every customer system has the same risk profile or control set.

02

Information ownership and classification

Information is handled according to its owner, sensitivity, contractual restrictions, and legal obligations. Customer information remains customer information; access does not transfer ownership.

  • Public: approved for public distribution.
  • Internal: limited to ResoluteX operations and authorised collaborators.
  • Confidential: customer, commercial, personal, or security information requiring controlled access.
  • Restricted: credentials, regulated records, production secrets, and other information requiring the strongest practical controls.
03

Access and identity

Access is granted for a defined purpose, limited to the minimum practical permissions, and reviewed when responsibilities change. Customer-controlled identities and repositories are preferred wherever the delivery model permits them.

  • Individual accounts rather than shared credentials.
  • Multi-factor authentication for systems that support it.
  • Secrets kept out of source code and shared only through approved channels.
  • Access removed at handover, role change, or the end of an engagement.
04

Secure delivery

Security work is proportional to the system being built. A public marketing site and a healthcare workflow do not receive the same threat model, evidence, or release controls.

  • Customer code is kept in agreed repositories with traceable changes.
  • Dependencies and open-source licences are reviewed as part of delivery.
  • Relevant functional, security, accessibility, and release checks are recorded.
  • Production changes, backups, logging, and recovery responsibilities are assigned before launch.
05

Data protection and residency

ResoluteX seeks to collect and retain only the information required for the stated purpose. Customer-hosted work follows the region and controls selected by the customer. Managed products follow their product terms and any signed processing agreement.

Encryption, retention, deletion, backup, and export requirements are documented for the actual deployment rather than implied by a company-wide marketing claim.

06

Suppliers and subprocessors

Third parties are selected for a defined role and receive only the information needed for that role. Material infrastructure, model, communication, or delivery providers are disclosed where the engagement or applicable law requires it.

Specialist partners remain accountable for regulated services such as employment, legal, tax, payroll, or insurance work; ResoluteX does not relabel their responsibilities as its own.

07

Incidents and continuity

Suspected security events are triaged, contained, investigated, and documented. Notification obligations and response contacts follow the affected contract and applicable law.

Recovery planning is based on the service boundary: the owner of backups, restore testing, infrastructure, and customer communication must be named before production use.

08

People, review, and reporting

Personnel are expected to protect credentials, report suspicious activity, follow customer security requirements, and avoid moving customer information into unapproved tools. This policy is reviewed when material technology, legal, or operating changes make an update necessary.

Report a vulnerability or security concern to engineering@resolutexhq.com. Please do not include production credentials or sensitive personal data in the first email.