Steadfast, unwavering security
Cybersecurity that fits a small business.
You don't need a security team or a six-figure budget. You need clear answers about whether your business is exposed — and a list of what to fix, in order.
See your security grade — A through F — in about 15 seconds. No account, no credit card.
Ready for the full platform? Start a free 14-day Pro trial — no card required.
See pricing · Talk to a security expert · Already have an account? Sign in →
Who this is for
If any of these sound like you, you're in the right place.
You're the founder
And also the IT person. And the CFO. And the operations lead. You don't have time to read an RFC.
Your customers are asking
A bigger client wants a security questionnaire filled out. Or you're trying to land a federal contract. Or your insurer changed your rates.
You got phished
Someone clicked a link. Maybe it was a wire transfer that almost happened. You're done hoping it doesn't happen again.
What you can do
Pick the problem. We have a tool for it.
Stop email impersonation
Free 15-second scan — no account needed.
Attackers love sending invoices that look like they're from your business. We check the settings (SPF, DKIM, DMARC) that tell other email servers to reject anything that isn't actually you.
- • See whether bad actors can spoof your domain right now
- • Get a plain-English fix for every problem we find
- • Continuous monitoring so a contractor can't break it later
Lock down your website
TLS, security headers, cookies, mixed-content, open-redirect — five tools, one subscription.
Your customers' browsers grade your site silently. The wrong settings let attackers steal logins, hijack pages, or sneak in fake content. We grade your site the way browsers do — and tell you exactly what to change.
- • Catches expired certificates before browsers do
- • Flags the headers Google PageSpeed never tells you about
- • Finds login pages that can be hijacked for phishing
Prove you're secure
Free to start. Built for the founder doing the assessment, not the consultant billing for it.
Enterprise customers and government contracts want a SOC 2 letter or a CMMC self-assessment before they sign. We walk you through every control in plain English, save the evidence, and export the report your auditor expects.
- • SOC 2 Trust Services Criteria, in your own words
- • CMMC Level 2 / NIST 800-171 — all 110 controls
- • Same evidence library across every framework
How it works
Three steps. Today.
- 1
Scan for free
Type your domain. We check eight things in 15 seconds. No account, no credit card. You'll see exactly where you stand.
- 2
Fix what's broken
Every problem comes with a copy-pasteable fix. If you have a vendor (Google Workspace, GoDaddy, Cloudflare), we tell you which menu to click.
- 3
Stay secure on autopilot
Continuous monitoring catches it when a contractor changes a DNS record or your hosting provider rotates a certificate. We tell you before customers notice.
Why Resolute Security
We're a security firm shipping the tools we wish existed.
Built for SMBs, not Fortune 500
Vanta-priced platforms assume you have a 30-person security team. We assume you have one person with five other jobs. Every tool ships with a fix list before it ships with a dashboard.
Read-only. We only check what's public.
We don't install agents on your servers. We don't ask for cloud credentials. Everything we check is already visible to attackers — we just point at it.
One subscription, one evidence library
Email security findings show up in your SOC 2 evidence library automatically. No double-entry. No second login. Same audit log across every tool.
AI-native · honest by design
AI that can read your compliance posture. And can never inflate your score.
Connect Resolute to Claude, Cowork, or any AI agent. It reads your real findings, evidence gaps, and CMMC readiness — and with your explicit consent, files findings and attaches evidence. But the moment an AI writes anything, that write is stamped, shown as AI-attested, and capped to a partial suggestion a human confirms. We didn't build AI that does your compliance for you. We built AI that can't quietly tell your auditor you're more ready than you are.
Ask what to fix next
An in-app copilot on every page. On Pro, when AI is configured, it reads your real posture scores, framework readiness, evidence gaps, and open findings and answers from those measured numbers. On free, or without an AI key, the same assistant runs as a helpful generic advisor — the UI tells you which mode you're in. It has no write tools, so it will never claim it changed or fixed anything.
Evidence, mapped to your controls
Connect the tools you already run — M365, GitHub, Cloudflare, Kisi, UniFi, Meraki, AWS, Snyk — and Resolute reads their telemetry and suggests CMMC answers with the exact measured fact shown as proof (your MFA enrollment percentage straight from M365, for example). It's a deterministic rule mapping your telemetry to controls, not a guess. You review and apply; it never overwrites your answers, and a tool that only sees part of a control is capped to "partial".
Connect your AI agent over MCP
Add Resolute to Claude or Cowork over the Model Context Protocol. Your agent reads your posture, findings, framework readiness, evidence gaps, vendor risk, and audit log — read-only by default, scoped to your org, secrets stripped at the wire. Grant write access at the consent screen and it can file findings and attach evidence; an API key never can.
tools.resolute-security.com/api/mcp Honest by design — a score AI can't inflate
When an agent records a fact it's saved as an attestation, never a measurement: the CMMC engine caps it to "partial", insurance readiness excludes it entirely, and a finding an agent files can only lower a score, never raise one. And you can see every one — each agent write shows an "AI-attested" badge and is filterable under "AI agent" in your activity log.
AI can suggest. Only a human confirms. The cap is enforced in code, not policy.
Read-only by default. Write access takes an explicit OAuth consent, and anything an agent records is marked as an attestation — it suggests “partial” readiness for a human to confirm, is excluded from any auto-confirmed score, and can't satisfy a freshness gate. No AI tool can inflate your measured posture — that guarantee is enforced in the compliance and insurance engines, not just written here.
Works with Claude, Cowork, and any MCP-compatible client. The Ask Resolute copilot is there the moment you log in; on Pro it answers from your own numbers. Connecting an agent to your posture over MCP is a Pro feature — the public record-validator endpoint needs no account at all.
For developers: connect over standards-based OAuth 2.1 with PKCE — read tools are scoped to your credential and secrets are stripped at the wire. Separately, a free no-login endpoint exposes pure record validators (SPF, DKIM, DMARC, CSP, HSTS) any agent can call — it parses what you paste and touches no account data. Read the connect guide →
Security intelligence & free resources
Open knowledge surfaces you can use without an account — threat trends, a compliance calendar, a plain-English glossary, and more.
Threat Radar
See which vulnerabilities are being actively exploited right now (CISA KEV), ranked for the SMB stack.
Explore →SMB Threat Landscape
The ransomware, phishing, and business-email-compromise trends actually hitting small businesses — every figure hand-sourced.
Explore →Compliance Calendar
The regulatory and framework deadlines that sneak up on you, laid out so nothing lapses while you're heads-down running the business.
Explore →Security Glossary
Every acronym an auditor or insurer throws at you — DMARC, CMMC, CVSS — explained in plain English, one term at a time.
Explore →Phishing Red-Flags Gallery
Annotated, real-world lures showing the tells your team can learn to spot before they click — no login required.
Explore →Security Self-Check
A short maturity quiz that scores where you stand across MFA, backups, patching, and email — and points at what to fix first.
Explore →Security Tips
A rotating library of one-step-at-a-time security tips for the founder doing five other jobs. One concrete move a day.
Explore →What's new
Shipped this month
Jun 27, 2026 · New
A sub-navigator on every Compliance, Posture, and Integrations page
Those three sections pack in the most tools, and it was hard to see what else lived there. Each page now opens with a compact, grouped sub-navigator listing every sibling page — the current one highlighted, a hover blurb explaining what each does, and Pro tools marked. It runs off one shared navigation manifest, so more sections (and richer public-site menus) follow from here.
Jun 27, 2026 · New
Your brand colour, across the pages you send out
Set a brand colour under Settings → Branding and it flows to the pages your customers and employees see: policy shares and security-training links pick up your accent, and it becomes the default colour on your public trust page (unless you've already chosen a trust-specific accent). Leave it blank to use the Resolute default.
Jun 27, 2026 · New
Your logo on the training and policies you send out
The security-awareness training links your employees open and the policy share pages you send to customers now carry your company's logo, so they look like they came from you. The Resolute credit sits quietly in the footer. Set your logo under Settings → Branding; a shared brand colour across these pages is coming next.
See what your business looks like to attackers.
Free scan. PDF report on request. About 15 seconds.