Skip to content

AI-native · honest by design

AI that can read your compliance posture. And can never inflate your score.

Connect Resolute to Claude, Cowork, or any AI agent. It reads your real findings, evidence gaps, and CMMC readiness — and with your explicit consent, files findings and attaches evidence. The moment an AI writes anything, that write is stamped, shown as AI-attested, and capped to a partial suggestion a human confirms.

The wedge

Most AI compliance tools ask you to trust a black box. We built one you can audit.

Here, AI is a collection-and-suggestion layer — never the decision-maker. It gathers evidence, spots gaps, and drafts answers. The human and the measured integrations stay authoritative. Every number an agent touches is marked as its work and held below the threshold that would count, so you can always see exactly what the AI did and what it didn't.

Woven, not bolt-on

Where AI sits in the loop

Read, suggest, collect, confirm — AI is threaded through the workflow, never bolted to the end of it. Each step answers to a human or a measured integration.

  1. 1

    Read posture

    The copilot and any connected agent read your real findings, evidence gaps, framework readiness, and next actions — the current stored picture, never an invented one.

    Copilot + MCP reads
  2. 2

    Suggest answers

    Your connected integrations are mapped to controls by a deterministic rule engine — not a model — so a CMMC control comes pre-filled with the evidence you already have.

    Deterministic auto-evidence
  3. 3

    Collect via agent

    With explicit consent, an agent can attach evidence to a control and file a tracked finding. Every write is additive and stamped as coming from an AI agent.

    MCP writes, consented
  4. 4

    Human confirms

    Anything an agent records is capped to a partial attestation. A person reviews it and decides whether it counts. The measured score stays yours to move.

    Attestation cap
The honesty stack

Three layers that make “never inflate your score” structural

It isn't a promise — it's three independent mechanisms in code: where the write is stamped, how far it's allowed to count, and how plainly it's disclosed.

Layer 1

Provenance

The moment an agent writes anything, the database row is stamped source='mcp' on the server. The agent can't set, spoof, or override that stamp — provenance is recorded where the data lands, not where it claims to come from.

Layer 2

The cap

An AI-written fact is capped to “partial” in the CMMC engine, excluded from insurance auto-fill, and blocked at the live-feed freshness gate. A finding an agent files can only lower a readiness number, never raise it.

The same discipline applies to measured integrations: even a perfect reading from a slice-only source — UniFi wireless, Meraki perimeter — is held to “partial” by a scope cap (maxStatus:'partial'), because one slice of your stack isn't the whole control.

Layer 3

Visible disclosure

An “AI-attested” badge appears wherever an AI-written fact shows. The activity log carries an “AI agent” filter so you can see every agent action in one place. The CMMC pre-fill panel notes inline when a suggestion was AI-attested and why it's held to partial.

For developers

Connect your agent

An authenticated MCP server your AI client connects to. Read-only by default; write access is a deliberate, per-connection grant.

MCP endpoint

tools.resolute-security.com/api/mcp

Streamable HTTP. Pro-gated. Org-scoped by the credential — no tool accepts an organizationId, and secrets are stripped at the wire. Full tool reference →

OAuth discovery

/.well-known/oauth-authorization-server

OAuth 2.1 + PKCE (S256) browser consent — the flow Claude uses — with Dynamic Client Registration and a published discovery document.

What an agent can read

Posture scores and trend
Open findings and their detail
Framework readiness (SOC 2, CMMC, NIST CSF)
Evidence gaps and next actions
Vendor and third-party risk
Monitored domains
Policies
Team MFA enrollment
DMARC data per domain
The audit log

What an agent can write — and what it can't

evidence_submit

What it does

Attaches evidence to a control so the work you've already done is on the record.

What it can't

Cannot mark the control met, satisfied, or compliant — it adds evidence, it doesn't grade.

finding_create

What it does

Files a tracked issue an agent has spotted, so nothing it notices gets lost.

What it can't

Cannot resolve, close, or delete anything — and a filed finding can only lower a score.

profile_fact_set

What it does

Records a posture fact the agent gathered about your environment.

What it can't

Lands as a partial attestation a human confirms — it never counts toward a measured score.

Two credentials, two levels of access

An smb_ API key

Read-only, always. It can ask every read tool above and nothing more — it can never write.

An OAuth token

Can be granted read + write at the consent screen, where you tick the write box for that connection. Until you do, the same token is read-only.

What a read actually returns

  • Reads return your current STORED posture — the last scoring run, the last scan — not an on-demand scan kicked off by the question.
  • A null score means “not enough data yet,” never zero. An agent that sees null shouldn't report a failing grade.
  • CMMC readiness is a control-response ratio — how many controls you've answered — not an SPRS score.
  • Transport is Streamable HTTP only. There is no SSE or WebSocket lane.
No account

Try it with no account

A separate public MCP lane your agent can hit before you ever sign up. It parses and analyzes records you paste — it doesn't scan anything.

tools.resolute-security.com/api/mcp-public

Hand it an SPF record, a DMARC policy, a CSP header, a certificate, or a token, and it analyzes the string you supplied. Plainly:

  • It shares no code path with the posture tools and reads none of your account data.
  • It makes no network calls — it parses what you give it.
  • The JWT tool decodes a token to show you its contents; it does not verify the signature.
Try the public validators →
In-app copilot

Ask Resolute

A copilot on every authenticated page — it answers what to fix next and what a finding means.

On Pro, when AI is configured, it answers from your real numbers — your scores, frameworks, and open findings. On the free tier, or without an AI key, the same assistant is a helpful generic advisor, and the panel shows you which mode you're in.

It has no write tools. And a scripted fallback means the panel is never blank, even when the model is unreachable.

The guarantees

What AI won't do

The limits are the point. Each of these is enforced in code, not left to good intentions.

No auto-remediation

The auto-fix feature is a copy-paste preview. It shows you the record or setting to change; it never reaches into your DNS or your stack to push it.

No marking controls met

No AI path can flip a control to met, satisfied, compliant, or audit-ready. That judgment stays with a person.

No inflating scores

AI-written facts are capped to partial and excluded from any auto-confirmed number. A finding an agent files can only move a score down.

No inventing facts

Reads return what's stored. A missing number reads as null — “not enough data yet” — not as a fabricated value.

No fabricated metrics

We don't manufacture time-saved percentages, readiness jumps, or confidence scores to make the AI look better than it is.

Connect your agent. Keep your humans in charge.

Read your real posture over MCP, let an agent collect evidence with your consent, and keep every measured score yours to move.