Trust Center
Security at Resalute Ops360
This page is maintained by Resalute Core Services LLC to answer common security and privacy questions about Resalute Ops360. It describes controls that are currently enabled in the platform. It is not a certification, audit report or independent verification.
Organization-level data isolation
Every operational table enforces row-level security scoped to the signed-in user's organization. Queries cannot reach another organization's records even if the application layer is bypassed.
Role-based access control
Roles (administrator, contract manager, field technician, property manager, government customer, vendor) are stored separately from user profiles and checked by security-definer database functions. Administrator access is granted only by an existing administrator.
Audit logging
Compliance-relevant record changes are written to an append-only audit log capturing the actor, action, entity and before/after state.
Encrypted transport and private storage
All traffic is served over TLS. Inspection photos and field media are stored in a private bucket that is not publicly listable and is reachable only through authenticated, access-checked requests.
Operational monitoring
Application errors and background job failures are captured centrally so issues can be investigated and resolved quickly.
Payment handling
Subscription payments are processed by Stripe. Card numbers are entered directly with Stripe and are never transmitted to or stored on Resalute systems.
Shared responsibility
Resalute operates the platform: hosting, database security, access enforcement, encryption in transit, patching and monitoring.
Your organization manages who is invited, which roles they hold, what data is uploaded, and whether that data is appropriate for a commercial cloud platform.
Your customers and agencies may impose additional contractual requirements. Contact us before storing data subject to controls we have not agreed to in writing.
Reporting a vulnerability
If you believe you have found a security issue, email ops360@resalutecoreservices.com with steps to reproduce. Please do not publicly disclose the issue before we have had a reasonable opportunity to respond. We acknowledge reports within two business days.
Compliance and certifications
Resalute Ops360 supports compliance workflows — QASP tracking, SOW mapping, CLIN burn rates, vendor insurance monitoring and audit trails. The platform itself does not claim SOC 2, ISO 27001, FedRAMP, HIPAA or PCI certification. For a specific compliance questionnaire, contact us directly.