Skip to content
Resolute SecurityRESOLUTESECURITY

Steadfast, unwavering security

Cybersecurity that fits a small business.

You don't need a security team or a six-figure budget. You need clear answers about whether your business is exposed — and a list of what to fix, in order.

See your security grade — A through F — in about 15 seconds. No account, no credit card.

Ready for the full platform? Start a free 14-day Pro trial — no card required.

See pricing · Talk to a security expert · Already have an account? Sign in →

Who this is for

If any of these sound like you, you're in the right place.

You're the founder

And also the IT person. And the CFO. And the operations lead. You don't have time to read an RFC.

Your customers are asking

A bigger client wants a security questionnaire filled out. Or you're trying to land a federal contract. Or your insurer changed your rates.

You got phished

Someone clicked a link. Maybe it was a wire transfer that almost happened. You're done hoping it doesn't happen again.

What you can do

Pick the problem. We have a tool for it.

Stop email impersonation

Free 15-second scan — no account needed.

Attackers love sending invoices that look like they're from your business. We check the settings (SPF, DKIM, DMARC) that tell other email servers to reject anything that isn't actually you.

  • • See whether bad actors can spoof your domain right now
  • • Get a plain-English fix for every problem we find
  • • Continuous monitoring so a contractor can't break it later
Check my email →

Lock down your website

TLS, security headers, cookies, mixed-content, open-redirect — five tools, one subscription.

Your customers' browsers grade your site silently. The wrong settings let attackers steal logins, hijack pages, or sneak in fake content. We grade your site the way browsers do — and tell you exactly what to change.

  • • Catches expired certificates before browsers do
  • • Flags the headers Google PageSpeed never tells you about
  • • Finds login pages that can be hijacked for phishing
Audit my site →

Prove you're secure

Free to start. Built for the founder doing the assessment, not the consultant billing for it.

Enterprise customers and government contracts want a SOC 2 letter or a CMMC self-assessment before they sign. We walk you through every control in plain English, save the evidence, and export the report your auditor expects.

  • • SOC 2 Trust Services Criteria, in your own words
  • • CMMC Level 2 / NIST 800-171 — all 110 controls
  • • Same evidence library across every framework
Start an assessment →

How it works

Three steps. Today.

  1. 1

    Scan for free

    Type your domain. We check eight things in 15 seconds. No account, no credit card. You'll see exactly where you stand.

  2. 2

    Fix what's broken

    Every problem comes with a copy-pasteable fix. If you have a vendor (Google Workspace, GoDaddy, Cloudflare), we tell you which menu to click.

  3. 3

    Stay secure on autopilot

    Continuous monitoring catches it when a contractor changes a DNS record or your hosting provider rotates a certificate. We tell you before customers notice.

Why Resolute Security

We're a security firm shipping the tools we wish existed.

Built for SMBs, not Fortune 500

Vanta-priced platforms assume you have a 30-person security team. We assume you have one person with five other jobs. Every tool ships with a fix list before it ships with a dashboard.

Read-only. We only check what's public.

We don't install agents on your servers. We don't ask for cloud credentials. Everything we check is already visible to attackers — we just point at it.

One subscription, one evidence library

Email security findings show up in your SOC 2 evidence library automatically. No double-entry. No second login. Same audit log across every tool.

AI-native · honest by design

AI that can read your compliance posture. And can never inflate your score.

Connect Resolute to Claude, Cowork, or any AI agent. It reads your real findings, evidence gaps, and CMMC readiness — and with your explicit consent, files findings and attaches evidence. But the moment an AI writes anything, that write is stamped, shown as AI-attested, and capped to a partial suggestion a human confirms. We didn't build AI that does your compliance for you. We built AI that can't quietly tell your auditor you're more ready than you are.

Ask what to fix next

An in-app copilot on every page. On Pro, when AI is configured, it reads your real posture scores, framework readiness, evidence gaps, and open findings and answers from those measured numbers. On free, or without an AI key, the same assistant runs as a helpful generic advisor — the UI tells you which mode you're in. It has no write tools, so it will never claim it changed or fixed anything.

Evidence, mapped to your controls

Connect the tools you already run — M365, GitHub, Cloudflare, Kisi, UniFi, Meraki, AWS, Snyk — and Resolute reads their telemetry and suggests CMMC answers with the exact measured fact shown as proof (your MFA enrollment percentage straight from M365, for example). It's a deterministic rule mapping your telemetry to controls, not a guess. You review and apply; it never overwrites your answers, and a tool that only sees part of a control is capped to "partial".

Connect your AI agent over MCP

Add Resolute to Claude or Cowork over the Model Context Protocol. Your agent reads your posture, findings, framework readiness, evidence gaps, vendor risk, and audit log — read-only by default, scoped to your org, secrets stripped at the wire. Grant write access at the consent screen and it can file findings and attach evidence; an API key never can.

tools.resolute-security.com/api/mcp

Honest by design — a score AI can't inflate

When an agent records a fact it's saved as an attestation, never a measurement: the CMMC engine caps it to "partial", insurance readiness excludes it entirely, and a finding an agent files can only lower a score, never raise one. And you can see every one — each agent write shows an "AI-attested" badge and is filterable under "AI agent" in your activity log.

AI can suggest. Only a human confirms. The cap is enforced in code, not policy.

Read-only by default. Write access takes an explicit OAuth consent, and anything an agent records is marked as an attestation — it suggests “partial” readiness for a human to confirm, is excluded from any auto-confirmed score, and can't satisfy a freshness gate. No AI tool can inflate your measured posture — that guarantee is enforced in the compliance and insurance engines, not just written here.

Works with Claude, Cowork, and any MCP-compatible client. The Ask Resolute copilot is there the moment you log in; on Pro it answers from your own numbers. Connecting an agent to your posture over MCP is a Pro feature — the public record-validator endpoint needs no account at all.

For developers: connect over standards-based OAuth 2.1 with PKCE — read tools are scoped to your credential and secrets are stripped at the wire. Separately, a free no-login endpoint exposes pure record validators (SPF, DKIM, DMARC, CSP, HSTS) any agent can call — it parses what you paste and touches no account data. Read the connect guide →

Free resources

Security intelligence & free resources

Open knowledge surfaces you can use without an account — threat trends, a compliance calendar, a plain-English glossary, and more.

Threat Radar

See which vulnerabilities are being actively exploited right now (CISA KEV), ranked for the SMB stack.

Explore →

SMB Threat Landscape

The ransomware, phishing, and business-email-compromise trends actually hitting small businesses — every figure hand-sourced.

Explore →

Compliance Calendar

The regulatory and framework deadlines that sneak up on you, laid out so nothing lapses while you're heads-down running the business.

Explore →

Security Glossary

Every acronym an auditor or insurer throws at you — DMARC, CMMC, CVSS — explained in plain English, one term at a time.

Explore →

Phishing Red-Flags Gallery

Annotated, real-world lures showing the tells your team can learn to spot before they click — no login required.

Explore →

Security Self-Check

A short maturity quiz that scores where you stand across MFA, backups, patching, and email — and points at what to fix first.

Explore →

Security Tips

A rotating library of one-step-at-a-time security tips for the founder doing five other jobs. One concrete move a day.

Explore →

See what your business looks like to attackers.

Free scan. PDF report on request. About 15 seconds.