Skip to content

Legal

Privacy Policy

Effective 2026-06-11.

Resolute Security("Resolute," "we," "us") provides the Resolute Security platform("Service"). This Policy explains what data we collect, why, how we use it, how we share it, and the choices and rights you have. It applies to our marketing site, the authenticated app, and the transactional email we send.

1. What we collect

  • Account data: email address, name (if you provide one), organization name, hashed password (if password sign-in is enabled), MFA secret (if you enroll), OAuth account identifiers when you sign in via Google or Microsoft.
  • Subscription data: Stripe customer and subscription identifiers, plan tier, billing status. Card details are stored with Stripe, not us.
  • Scan and monitoring data: domain names you submit, DNS query results, scoring metadata. We deliberately do not store SMTP message contents, mailbox contents, or any personally identifiable mail data.
  • Compliance content: the answers, notes, and evidence you upload while completing CMMC / SOC 2 / NIST CSF assessments and vendor questionnaires.
  • Integration data: when you connect a third-party service (e.g. Microsoft 365, Google Workspace, AWS, GitHub, or other supported integrations), we pull the security- and compliance-relevant configuration, posture, and event data that integration exposes — and store the access tokens needed to do so in encrypted form. We request the narrowest scopes the feature needs.
  • Usage and telemetry: product analytics about how you interact with the Service (pages and features used, actions taken, approximate timing) and diagnostic / error telemetry, used to keep the Service reliable and to improve it.
  • Operational data: IP addresses, user-agent strings, audit-log events (sign-in, configuration changes), session metadata. Used for security forensics and rate limiting.
  • Support communications: the contents of emails, messages, and requests you send us (including via the in-app contact widget), so we can respond and keep a record of the conversation.
  • Cookies and local storage: a small number of strictly-necessary cookies plus browser local storage used to keep you signed in, remember your current organization, and protect against abuse. See section 9 and our Cookie Policy.
  • Email-deliverability signals:bounce / complaint events forwarded to us by Resend for the addresses we've sent transactional email to.

2. How we use it

  • Provide the Service and the features your plan includes.
  • Send you transactional email (sign-in links, scan reports, drift alerts, billing receipts, weekly digests when you opt in).
  • Detect, prevent, and respond to abuse, fraud, and security incidents.
  • Improve the product. We don't train AI models on your data.
  • Comply with legal obligations.

3. Legal bases for processing (EEA/UK)

If you are in the European Economic Area or the United Kingdom, we process your personal data under one or more of the following GDPR legal bases:

  • Performance of a contract — to provide the Service to you (or your organization) and meet our commitments under our Terms and any DPA.
  • Legitimate interests — to secure, maintain, and improve the Service, prevent fraud and abuse, and run our business, where those interests are not overridden by your rights.
  • Consent — where we ask for it, such as optional communications; you can withdraw consent at any time.
  • Legal obligation — to comply with applicable law, regulation, or a valid legal request.

4. How we share your data

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We share data only in these limited ways:

  • Service providers / sub-processors: a small set of vendors that operate the Service on our behalf — managed Postgres, transactional email, payments, error monitoring, etc. Each is bound by their own privacy and security commitments and a data-processing agreement with us. See the full, regularly-updated list at /sub-processors.
  • Legal and safety disclosures: when we reasonably believe disclosure is required by law, regulation, legal process, or government request, or is necessary to protect the rights, property, or safety of Resolute, our users, or the public.
  • Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, your data may be transferred as part of that transaction. We will require the recipient to honor this Policy or notify you of any material change.

5. How long we keep your data

  • Account and compliance content: as long as your account is active. You can delete your account at any time, which removes your data within 30 days (backups age out per schedule).
  • Scan results: retained for plan-tier-dependent windows so historical diffs work; see your plan's details.
  • Audit logs: 12 months. Sign-in / configuration history is kept for security forensics.
  • Magic-link tokens and expired sessions: pruned by a daily cleanup job.

6. Your rights

Depending on where you live, you may have some or all of the following rights over your personal data:

  • EEA/UK (GDPR):access, correction, deletion ("erasure"), data portability, restriction of processing, objection to processing, and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data-protection authority.
  • California (CCPA/CPRA) and similar US state laws: the right to know what we collect and how we use and disclose it, to access and delete your personal information, to correct inaccurate information, to opt out of the "sale" or "sharing" of personal information (we do not sell or share it), and to not be discriminated against for exercising your rights.

Many of these are self-serve via your account settings. For anything else, including verified access, export, or deletion requests, file a request at /your-rights and we'll respond within the timeframe the applicable law requires (generally within 30–45 days). You may use an authorized agent to submit a request where the law allows.

7. International transfers

We host the Service in the United States. If you access the Service from outside the US, your data is transferred to and processed in the US. For EEA/UK residents we rely on Standard Contractual Clauses and equivalent transfer mechanisms with our sub-processors where required.

8. Security

We maintain reasonable administrative, technical, and physical safeguards designed to protect your data: TLS in transit, encryption of sensitive credentials and integration tokens, database-level isolation of customer data, access controls, and audit logging of every configuration change. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators without undue delay as required by applicable law.

9. Children

The Service is intended for businesses and is not directed to anyone under 18, and in no case to children under 13 (or under 16 where a higher age applies). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

10. Cookies and tracking

We only set strictly-necessary cookies (session, security, impersonation, current-org) and use limited browser local storage; we do not use third-party advertising trackers. See our Cookie Policy for the full list and details.

11. Customer (B2B) personal data

When you use the Service on behalf of an organization, that organization is the controller of the personal data it submits or that we collect from its connected integrations, and Resolute Security acts as its processor. Our handling of that data is governed by our Data Processing Addendum, which is published in full and applies automatically to every paid subscription. If your personal data was provided to us by an organization using the Service, please direct rights requests to that organization; we will assist them as the DPA requires. Need a countersigned DPA for your procurement file? Email [email protected].

12. Changes to this policy

We'll post updates here and update the effective date above. Material changes will be announced by email when we have one on file. Your continued use of the Service after an update takes effect means you accept the revised Policy.

13. Contact

Privacy questions or rights requests: [email protected]. Or file a request directly via /your-rights.