Trust Center

Security at Resalute Ops360

This page is maintained by Resalute Core Services LLC to answer common security and privacy questions about Resalute Ops360. It describes controls that are currently enabled in the platform. It is not a certification, audit report or independent verification.

Organization-level data isolation

Every operational table enforces row-level security scoped to the signed-in user's organization. Queries cannot reach another organization's records even if the application layer is bypassed.

Role-based access control

Roles (administrator, contract manager, field technician, property manager, government customer, vendor) are stored separately from user profiles and checked by security-definer database functions. Administrator access is granted only by an existing administrator.

Audit logging

Compliance-relevant record changes are written to an append-only audit log capturing the actor, action, entity and before/after state.

Encrypted transport and private storage

All traffic is served over TLS. Inspection photos and field media are stored in a private bucket that is not publicly listable and is reachable only through authenticated, access-checked requests.

Operational monitoring

Application errors and background job failures are captured centrally so issues can be investigated and resolved quickly.

Payment handling

Subscription payments are processed by Stripe. Card numbers are entered directly with Stripe and are never transmitted to or stored on Resalute systems.

Shared responsibility

Resalute operates the platform: hosting, database security, access enforcement, encryption in transit, patching and monitoring.

Your organization manages who is invited, which roles they hold, what data is uploaded, and whether that data is appropriate for a commercial cloud platform.

Your customers and agencies may impose additional contractual requirements. Contact us before storing data subject to controls we have not agreed to in writing.

Reporting a vulnerability

If you believe you have found a security issue, email ops360@resalutecoreservices.com with steps to reproduce. Please do not publicly disclose the issue before we have had a reasonable opportunity to respond. We acknowledge reports within two business days.

Compliance and certifications

Resalute Ops360 supports compliance workflows — QASP tracking, SOW mapping, CLIN burn rates, vendor insurance monitoring and audit trails. The platform itself does not claim SOC 2, ISO 27001, FedRAMP, HIPAA or PCI certification. For a specific compliance questionnaire, contact us directly.