Security & Compliance

Our commitment to
security, privacy,
and trust.

ResolvX is built on the premise that financial dispute resolution requires the highest standards of data protection. This page documents how we protect your data, our control environment, and our path to independent certification.

ISO 27001:2022 : Aligned
SOC 2 Type II : Fully Ready
GDPR : Aligned
NIST CSF 2.0 : Aligned
NIST SP 800-61 : Implemented
77/93
ISO 27001 Controls Implemented
6/6
Tier 1 Vendors Assessed
100%
MFA Enforced
Across All Systems
0
Major Nonconformities
(Re-Audited 2026-07-31)
Last updated: 2026-07-31

Document Library

ResolvX is proud to showcase its six-phase GRC programme — now spanning 26 policies across every control domain. Public documents link directly to the project repository.
Confidential documents require a signed NDA - request access via security@resolvx.io.

48 documents
Phase 1 Programme Foundation
📄
Programme Charter & Scope Definition
Objectives, scope, risk methodology, stakeholder register, programme roadmap
MD ● Public View Document →
🏠
Company Profile & Asset Inventory
ResolvX background, asset classification, information types, cloud environments
MD ● Public View Document →
Phase 2 Risk & Controls
📈🔒
Risk Register
25 risks across 5 domains : likelihood, impact, residual scores, heat map, treatment plan
XLSX 🔒 Confidential · NDA Request Access
📄🔒
Risk Summary Report
Risk posture overview, top residual risks, FAIR analysis, risk treatment plan, board recommendations
PDF 🔒 Confidential · NDA Request Access
📄
Risk Methodology
Description of the approach and techniques used for risk assessment and management
PDF● PublicView Document →
📋
ISO 27001:2022 Control Matrix
Full Annex A mapping - 93 controls, implementation status, control owners
XLSX ● Public View Document →
📋
SOC 2 TSC Criteria Mapping
CC1 - CC9 mapped against implemented controls, evidence references, gaps noted
XLSX ● Public View Document →
📊
NIST CSF 2.0 Function Mapping
GV, ID, PR, DE, RS, RC functions mapped to ResolvX controls
XLSX ● Public View Document →
Phase 3 Policies & Vendor Risk
📄
Information Security Policy (POL-001)
ISMS framework, objectives, risk appetite, control obligations - v1.0 Board Approved
PDF● PublicView Document →
📄
Acceptable Use Policy (POL-002)
Device use, remote work, data handling, AUP enforcement and disciplinary framework
PDF● PublicView Document →
📄
Access Control Policy (POL-003)
RBAC, MFA requirements, JML lifecycle, privileged access management, review cadence
PDF● PublicView Document →
📄
Data Classification Policy (POL-004)
4-tier scheme - Public, Internal, Confidential, Restricted - with handling rules per category
PDF● PublicView Document →
📄
Vendor Management Policy (POL-005)
TPRM framework, vendor tiering criteria, DPA requirements, SSO enforcement, review cadence
PDF● PublicView Document →
📄
Privacy Programme Policy (POL-006)
ROPA, DSR process, GDPR Art.30/33/34 obligations, controller vs processor distinctions
PDF● PublicView Document →
📄
Logging & Monitoring Policy (POL-007)
Log source coverage, retention, SIEM roadmap, correlation rules across 7 platforms
PDF● PublicView Document →
📄
BCP/DR Policy & Plan (POL-008)
RTO/RPO by criticality tier, activation authority, tested via DR failover tabletop
PDF● PublicView Document →
📄
Backup & Recovery Policy (POL-009)
Immutable backup copies, integrity verification, quarterly restoration testing
PDF● PublicView Document →
📄
Patch Management Policy (POL-010)
Severity-based SLA, emergency patching, continuous scanning with auto-ticketing
PDF● PublicView Document →
📄
Asset Management Policy (POL-011)
Formal asset register, quarterly reconciliation, authorized software list
PDF● PublicView Document →
📄
Password Policy (POL-012)
Password manager mandate, breach monitoring, break-glass credential handling
PDF● PublicView Document →
📄
Change Management Policy (POL-013)
3-tier change categorisation, peer review, automated rollback windows
PDF● PublicView Document →
📄
Risk Management Policy (POL-014)
Tiered risk acceptance authority, quarterly review, thematic root-cause clustering
PDF● PublicView Document →
📄
Incident Management Policy (POL-015)
Universal reporting obligation, declaration authority, insider/HR incident handling
PDF● PublicView Document →
📄
Breach Management Policy (POL-016)
EU/US notification framework, risk determination methodology, regulator templates
PDF● PublicView Document →
📄
Root Cause Analysis Policy (POL-017)
Five Whys methodology, repeat-finding escalation, effectiveness verification
PDF● PublicView Document →
📄
Secure SDLC Policy (POL-018)
Threat modelling triggers, secure coding standards, test data protection
PDF● PublicView Document →
📄
DLP Policy (POL-019)
Current DLP scope, phased tooling roadmap, formally accepted residual risk
PDF● PublicView Document →
📄
Data Destruction Policy (POL-020)
Destruction method by system type, legal hold process, crypto-shredding for backups
PDF● PublicView Document →
📄
Cryptography & Key Management Policy (POL-021)
Approved algorithms, key lifecycle, certificate management standards
PDF● PublicView Document →
📄
Cyber Security Policy (POL-022)
Network segmentation, endpoint hardening, cloud infrastructure baseline (CIS)
PDF● PublicView Document →
📄
HR Security Policy (POL-023)
Tiered screening, same-day termination revocation, dormant account reconciliation
PDF● PublicView Document →
📄
Physical & Environmental Security Policy (POL-024)
AWS shared-responsibility model, workspace access, regional environmental risk
PDF● PublicView Document →
📄
Clean Desk & Clear Screen Policy (POL-025)
Manual screen-lock expectation, physical document handling, remote workspace discretion
PDF● PublicView Document →
📄
Policy Exception Governance Policy (POL-026)
Tiered exception approval authority, duration limits by risk tier, quarterly review
PDF● PublicView Document →
📈🔒
Vendor Register & Tier 1 Assessments
14 vendors · 6 Tier 1 fully assessed with scoring · residual risk ratings
XLSX 🔒 Confidential · NDA Request Access
📂🔒
Sub-Processor Register
10 sub-processors · transfer mechanisms, SCC status, data scope, DPA references
XLSX 🔒 Confidential · NDA Request Access
Phase 4 Incident Response
🚨
Incident Response Plan (IRP)
Full NIST 800-61 lifecycle with roles, severity model, containment, regulatory notifications
PDF ● Public View Document →
🎮
Operational Runbooks : Phishing, Ransomware, Data Breach
3 playbooks covering detection through post-incident review and lessons learned
MD ● Public View Document →
📋🔒
Tabletop Exercise Report : Operation Locked Gate
Feb 2026 · 8 participants · ransomware scenario · findings and remediation tracking
PDF 🔒 Confidential · NDA Request Access
📈🔒
DR Failover Tabletop Report : Operation Steady Ground
Jul 2026 · full BCP/DR scenario · recovered within 98% of Critical-tier RTO budget
XLSX 🔒 Confidential · NDA Request Access
Phase 5 Audit Readiness
📋🔒
Internal Audit Checklist
31 ISO 27001 controls + 17 SOC 2 TSC criteria tested - detailed test results and evidence reviewed
XLSX 🔒 Confidential · NDA Request Access
📄🔒
Internal Audit Report
Re-audited 2026-07-31 · Satisfactory verdict · 0 major NCs · 0 minor NCs (was 5) · 2 observations remain
PDF 🔒 Confidential · NDA Request Access
🎯🔒
SOC 2 Type II Readiness Assessment
98% readiness · Fully Ready · all control gaps closed · auditor engagement in progress
PDF 🔒 Confidential · NDA Request Access
📈🔒
Corrective Action Plan
8 actions · 7 closed, 1 open · root cause, owner, due date, verification method
XLSX 🔒 Confidential · NDA Request Access
Phase 6 Trust Center & Dashboard
📊🔒
Compliance Dashboard
5-sheet internal CISO dashboard · programme status, risk overview, vendor, CAP, 2026 roadmap
XLSX 🔒 Confidential · NDA Request Access
🌐
Trust Center
Public-facing security posture, compliance status, document library, vendor security
● Public

How we protect your data

Our security programme is built across six phases, grounded in ISO 27001:2022, NIST CSF 2.0, and SOC 2 Trust Service Criteria.

🔐

Identity & Access Control

Multi-factor authentication is enforced for 100% of users via Okta. Role-based access control with quarterly access reviews. Privileged accounts require hardware FIDO2 keys. Zero standing access to production data.

Implemented
☁️

Cloud Infrastructure Security

Hosted exclusively on AWS in EU regions (eu-west-1, eu-central-1). AWS GuardDuty active in all regions. CloudTrail logging with S3 integrity validation. All data encrypted at rest (AES-256) and in transit (TLS 1.3).

Implemented
🔍

Vulnerability Management

Snyk integrated into all CI/CD pipelines for SAST and SCA scanning, with automatic ticket creation on High/Critical findings. Patch SLAs: Critical within 7 days, High within 30 days, Medium within 60 days, Low within 90 days. No High-severity findings open past SLA.

Implemented
📊

Monitoring & Detection

24/7 infrastructure monitoring via Datadog. GuardDuty threat detection with weekly findings review. Okta anomaly detection with impossible travel alerts. Centralised log management with 12-month retention.

Implemented

Standards and certifications

We align our ISMS to leading international standards. Our internal audit was re-performed 2026-07-31, confirming conformance across all tested controls with 0 open minor nonconformities (down from 5).

Framework Scope Status Evidence Last Assessed
ISO/IEC 27001:2022 Full ISMS. Across all systems, data, and personnel Aligned Internal audit re-performed 2026-07-31 ·
0 major NCs, 0 minor NCs
2026-07-31
SOC 2 Trust Service Criteria Security, Availability, Confidentiality Fully Ready Readiness: 98% (17/17 criteria Ready) · Auditor engagement in progress 2026-07-31
GDPR (EU) 2016/679 All personal data processing activities Compliant ROPA maintained · DPAs executed · DSR process live · Breach notification framework extended (EU/US) 2026-07-31
NIST CSF 2.0 GV, ID, PR, DE, RS, RC functions Aligned 82/103 subcategories Implemented · Gap analysis re-derived 2026-07-31 2026-07-31
NIST SP 800 - 61 Rev 2 Incident response lifecycle Implemented IR plan v1.1, 3 runbooks, 2 tabletops (Feb 2026 ransomware, Jul 2026 DR failover) 2026-07-31
NIST SP 800 - 53B (Moderate Baseline) Control selection reference Reference Used as supplementary control baseline Q4 2025

ISO 27001:2022 - Key Controls 77/93 Implemented

A5.1 Information Security Policies
A5.15 Access Control
A5.16 Identity Management
A5.19 Information Security in Supplier Relationships
A5.24 - A5.27 Incident Response Lifecycle
A5.34 Privacy and Protection of PII
A8.5 Secure Authentication (MFA)
A8.15 Logging / A8.16 Monitoring
A8.24 Use of Cryptography
A8.28 Secure Coding

SOC 2 TSC - Ready Families 9 / 9 Full

CC1 Control Environment
CC2 Communication & Information
CC3 Risk Assessment
CC4 Monitoring of Controls
CC5 Control Activities
CC6 Logical and Physical Access
CC7 System Operations
CC8 Change Management
CC9 Risk Mitigation - Vendor

How we handle your data

We process financial dispute data on behalf of regulated financial institutions. Our data handling practices reflect the sensitivity of this responsibility.

📍 Data Residency

  • All production data stored exclusively in AWS EU regions (eu-west-1, eu-central-1)
  • Data residency settings enforced in Google Workspace (EU)
  • No data transferred outside EEA without explicit contract provision and SCCs
  • Sub-processor transfer mechanisms documented (SCCs executed with all US sub-processors)

🔒 Encryption

  • AES-256 encryption at rest across all production databases and S3 buckets
  • TLS 1.3 enforced on all public endpoints - no legacy protocols permitted
  • AWS KMS for encryption key management with defined key rotation
  • 1Password zero-knowledge architecture for credential storage

⏱️ Retention and Deletion

  • Data retention periods defined per data category in our Data Classification Policy
  • Client data deleted or returned within 30 days of contract termination
  • Data Subject Requests (access, deletion, portability) handled within statutory timelines
  • Automated deletion workflows implemented for defined categories

👥 Access to Data

  • Strict need-to-know access - no employee has broad access to client data
  • All access to production data requires justification and time-limited approval
  • Quarterly access reviews by system owners; deprovisioning SLA of 48 hours
  • All access is logged and monitored via CloudTrail and Okta audit logs

📋 GDPR Obligations

  • ResolvX acts as data processor for client financial data; data controller for employee data
  • Data Processing Agreements (DPAs) executed with all clients and data-processing vendors
  • Record of Processing Activities (ROPA) maintained under GDPR Article 30
  • 72-hour breach notification to supervisory authority (Irish DPC) - documented process

📂 Sub-processors

  • Current sub-processor register maintained and available on request
  • 30-day advance notice to clients before adding or replacing material sub-processors
  • All sub-processors assessed against our vendor risk tiering framework
  • Key sub-processors: AWS (hosting), Google Workspace (collaboration), Okta (identity)

How we respond to security incidents

ResolvX maintains a documented, tested incident response programme aligned to NIST SP 800-61 Rev 2. Two tabletop exercises are now on record: a ransomware scenario (February 2026) and a full DR/BCP failover exercise (July 2026), which recovered within 98% of the Critical-tier RTO budget.

Detection & Declaration T+0

Incidents detected via AWS GuardDuty, Datadog, Okta anomaly detection, or staff reports. Severity classified P1–P4 within minutes of detection.

Containment P1: 15 min

Incident Response Team assembled. Affected systems isolated. Evidence preserved per chain-of-custody procedures. Out-of-band communications activated.

Client & Regulatory Notification

If your data is affected, we notify you as data controller within our DPA timelines (typically 24–72 hours). Personal data breaches notified to the Irish DPC within 72 hours of awareness.

Eradication & Recovery P1 RTO: 4hr

Root cause remediated. Systems restored from verified clean backups. Service restored per defined RTOs. 72-hour post-recovery monitoring.

Post-Incident Review

Lessons learned meeting within 5 business days of all P1/P2 incidents. Findings fed back into risk register and control improvements.

Response SLAs

Severity Initial Response Client Notification
P1 : Critical 15 minutes Within 24 hours
P2 : High 1 hour Within 48 hours
P3 : Medium 4 hours As required
P4 : Low Next business day N/A

To report a suspected security incident: security@resolvx.io
For urgent P1 issues, your account manager has our emergency contact line.

Our third-party risk programme

We operate a formal Third-Party Risk Management (TPRM) framework. All critical vendors are assessed annually. Data Processing Agreements are executed with every vendor that processes personal data.

Vendor Role Risk Tier SOC 2 / ISO 27001 DPA Status Data Processed
Amazon Web Services (AWS) Cloud Infrastructure Tier 1 SOC 2 Type II · ISO 27001 Active All production data
(EU regions)
Okta Identity & Access Management Tier 1 SOC 2 Type II Active Employee identity
(no client PII)
GitHub Source Code Management Tier 1 SOC 2 Type II · ISO 27001 (Microsoft) Active Source code only
(no client data)
Google Workspace Email & Collaboration
(EU residency)
Tier 1 SOC 2 Type II · ISO 27001 Active Internal comms
(EU data residency)
Datadog Monitoring & Observability Tier 2 SOC 2 Type II Active System logs (anonymised)
Stripe Payment Processing
(billing only)
Tier 2 PCI DSS Lvl 1 · SOC 2 Type II Active ResolvX billing only
(no client data)

Full sub-processor register available to clients upon request under NDA. Updated within 30 days of any material change.

Have security questions?

Our GRC team is available to answer questions about our security programme, share additional documentation under NDA, or schedule a security review call.