Security

Security your clients can trust.

Integration companies take on real responsibility when they put an AI in front of their highest-value clients. Here's exactly how Resolve protects them — and you.

The foundation

Encryption in transit

All traffic between clients, mobile apps, and servers is encrypted end-to-end with TLS 1.2+.

Encryption at rest

Database contents and uploaded media are encrypted at rest with AES-256 by our infrastructure provider.

Strict data isolation

PostgreSQL row-level security policies enforce per-company boundaries. Users can only access data belonging to their own residence and company.

Authentication & 2FA

Email/password, Sign in with Apple, and Sign in with Google. Admin portal supports TOTP-based two-factor authentication.

Audit logging

Every admin action — account approvals, document uploads, home edits, deletions — is written to a tamper-evident audit log retained for 12 months.

Signed, expiring URLs

Document downloads use time-limited signed URLs that expire within one hour, preventing link sharing or unauthorized access.

No ad SDKs, no trackers

The mobile app has no advertising identifiers, no analytics SDKs, and no third-party trackers. The admin portal uses only essential authentication cookies.

AI data handling

Primary AI provider (Google Gemini) runs on a paid commercial API where submitted data is not used for training. Our fallback path (OpenRouter) is configured to route only to providers that do not train on or retain submitted data.

Privacy framework

GDPR & CCPA aligned

Users can request access, correction, deletion, and portability of their data. EU/UK/Swiss users are covered by Standard Contractual Clauses for international transfers.

Processor relationship

Resolve operates as a data processor on your integration company's behalf. Your company is the controller. Our Data Processing Agreement spells out the full responsibilities of each side.

No training on your data

We don't train models on client conversations. Our primary AI provider's paid API terms explicitly prohibit training on submitted data.

Infrastructure

Cloud hostingVercel (US)
Database & authSupabase (Postgres on AWS us-east)
AI providersGoogle Gemini, OpenRouter
Email deliveryResend
Network monitoringDomotz (when enabled)
Text-to-speech (optional voice feature)ElevenLabs (when enabled)

Complete sub-processor list is maintained in our Privacy Policy §7.

Incident response

If a data breach compromises personal information, Resolve will notify affected users and partner companies within 72 hours of discovery, along with the relevant regulators where required by law. The notification will describe the scope, data affected, remediation steps, and protective recommendations.

Responsible disclosure

If you've discovered a vulnerability in Resolve, please report it privately before disclosing publicly. We'll acknowledge within one business day and work with you on a fix.

Send reports to security@resolveconcierge.com. Please include: steps to reproduce, the impact, and any proof-of-concept. We do not currently operate a paid bug bounty, but we will acknowledge your work publicly with permission.

We ask that researchers avoid actions that could degrade service for real users, access data belonging to anyone other than a test account you control, or exfiltrate sensitive data.

Ongoing work

Security is a moving target. Current initiatives:

  • Quarterly dependency audit and CVE review
  • Expanded RLS policy tests in CI pipeline
  • Continuous monitoring of authentication and admin actions
  • Formal third-party penetration testing (planned for post-Series A)
  • SOC 2 Type II attestation (planned as customer demand warrants)

Questions from your security team?

Happy to jump on a call with your IT, security, or compliance team. Send a note and we'll share architecture diagrams, sample DPAs, and more.