
Resolver, a Kroll company, maintains a comprehensive information security and privacy program designed to protect the confidentiality, integrity, and availability of client and corporate information.
Kroll is independently audited and certified against internationally recognized standards, including ISO/IEC 27001:2022, ISO/IEC 27701:2019, ISO/IEC 23301, Cyber Essentials Plus, and maintains TX-RAMP Level 2 certification. Kroll also undergoes a SOC 2 Type II audit covering the AICPA Trust Services Criteria for Security, Availability, and Confidentiality.
These certifications and attestations evaluate the design and operating effectiveness of Kroll's control environment across governance, risk management, access control, encryption, secure configuration, vulnerability management, incident response, and business continuity.
Kroll complies with applicable data protection and privacy laws and regulations, including EU and UK GDPR and other regional requirements depending on the nature of the engagement and data residency considerations. We operate under a shared responsibility model, working collaboratively with clients to ensure the appropriate use and protection of data.
Kroll conducts regular independent third-party penetration testing and security assessments covering infrastructure and applications. Executive summaries and remediation responses are made available to clients under NDA upon request.
Additional details regarding our certifications and assurance documentation are available within our Trust Center resources.

