At a glance
The data RESO holds
Account transcripts, Form 433 financials, identifiers, and the firm’s own work product all live on the case record. That is sensitive by definition, so the platform is built to firm-grade controls rather than consumer defaults.
The posture, plainly stated: encryption, isolation, role-aware access, and attestation.
How it’s protected
- Encryption in transit (TLS 1.2+) and at rest in storage, with app-layer encryption for sensitive identifiers
- Firm-scoped tenant isolation on every API path, with database RLS as defense-in-depth
- Role-aware access — Admin, Sales, and Resolution scopes per role
- Activity logging across the case record, with practitioner attestation on deliverables
- Security architecture documentation available for enterprise rollout review
Practitioner judgment stays required
Client-facing outputs are not auto-sent. A practitioner reviews and attests to deliverables before they leave the firm — so the human accountable for the work is always in the loop, and the record shows it.
Enterprise rollout
For large firms and enterprise deployments, ask about rollout options — including SSO and firm playbook configuration — during onboarding.