You’re trusting us with sensitive access and information. Here’s exactly how we protect it: our data residency, encryption, access controls, sub-processors and disclosure process, in the open.
The controls behind every engagement, the same practices we assess in our clients.
Client and evidence data is stored and processed in South Africa by default.
Strong encryption in transit and at rest across all systems.
Least-privilege access with phishing-resistant MFA everywhere.
Continuous monitoring of our own environment, 24/7.
Tested recovery so an incident never becomes a loss.
Trust starts with who we let near your systems.
The third parties we rely on to deliver our services, what they process, and where. We notify clients of material changes.
Found a security issue in our systems? We want to hear from you, and we won’t take legal action against good-faith research.
If you believe you’ve found a vulnerability affecting Resilitech, please report it privately so we can fix it before it’s disclosed. We aim to acknowledge reports within one business day.
Safe harbour: good-faith research conducted within this policy is authorised, and we will not pursue legal action for it.
Clients and prospects can request our ISO certificate, SOC 2 report and completed security questionnaires under NDA.