Strict content security policy
A unique cryptographic nonce on every request. No inline or third-party scripts can run.
Trust center
A security firm is judged first by how it protects itself. This page sets out what we do today, and what we will not claim until it is independently verified.
This website
Every control below can be verified with your browser’s developer tools or a public header scanner.
A unique cryptographic nonce on every request. No inline or third-party scripts can run.
HTTPS enforced with HSTS, so browsers never connect over plain HTTP.
Framing by other sites is blocked, content sniffing is disabled and powerful browser features are switched off.
No advertising cookies, analytics profiling or third-party trackers. The only cookie stores your theme.
Your visit is not shared with a font provider or content network for typography.
Contact-form submissions are validated on the server and are never written to application logs.
Client engagements
Secure development
Risks are identified at design time, not after build.
Tests are written to fail before the fix, then proved to pass.
Nothing merges without review, and risky changes get adversarial review.
Dependencies and secrets are scanned on every change.
Security testing evidence is produced before anything ships.
We design our controls around recognised frameworks, including ISO/IEC 27001, the NIST Cybersecurity Framework and the OWASP Application Security Verification Standard. We do not currently hold a formal certification, and we will not display one until it has been independently audited and awarded.
If we become aware of a security incident affecting client data, we contain it, investigate it and notify the affected client without undue delay, with the facts we have and the steps we are taking, in line with our contracts and the law.
Responsible disclosure
We welcome reports from security researchers. Report a suspected vulnerability in a Resolv system through our contact page, with enough detail for us to reproduce it.
Procurement and security teams can request further detail on any control. A senior engineer replies within one business day.