COMPLIANCE & SECURITY

Protecting Consumers. Protecting Clients. Protecting Data.

ResolveOne is being built around a compliance-first and security-focused approach to receivables management. Our goal is to support professional consumer engagement while protecting sensitive information through documented controls, responsible technology and appropriate oversight.

ResolveOne security and data protection

Compliance & Security By Design

Strong compliance and information security depend on people, processes, technology and consistent oversight working together.

01

Consumer Protection

Communication practices designed around applicable requirements, respectful treatment and documented procedures.

02

Data Protection

Security-focused safeguards designed to protect sensitive information throughout its lifecycle.

03

Controlled Access

Access to systems and information can be limited based on job responsibility and legitimate business need.

04

Monitoring & Oversight

Operational monitoring and documented records can support accountability, quality and response.

05

Business Continuity

Backup, recovery and continuity planning can support resilience and availability of important systems and information.

ResolveOne compliance workflow
REGULATION F AWARENESS

Keeping Pace With Compliance Changes.

ResolveOne’s compliance approach is designed around applicable federal and state collection requirements, including areas addressed by the FDCPA and Regulation F where relevant to a particular program.

Call-Frequency Controls
Time-of-Day Restrictions
Communication Preferences
Validation & Dispute Workflows
Electronic Communications
Recordkeeping & Audit Trails

Security Is Not an Add-On

Sensitive consumer and client information deserves layered protection. ResolveOne’s security-focused operating model is designed around physical, technical and procedural safeguards.

LAYERED SECURITY

Security and Compliance Are Built Into the Process.

From user access and workstation security to private connectivity, monitoring, backups and information handling, our approach is designed to reduce unnecessary exposure and support responsible management of sensitive information.

Private & Secure Connectivity Controlled private network and secure remote-access methods can help protect connections to sensitive systems and information.
Multi-Factor Authentication Additional verification can strengthen access to systems, applications and remote connectivity.
Encrypted Workstations Device encryption and managed workstation controls can help protect information stored on authorized business devices.
Role-Based / Need-to-View Access Sensitive information can be restricted based on assigned responsibilities and legitimate business need.
Firewall & Network Controls Managed network controls can help reduce unauthorized access and support a layered security model.
Session & Password Controls Strong authentication, protected sessions and automatic locking can help reduce unauthorized workstation access.
Monitoring & Logging Security and operational activity can be monitored and recorded to support oversight and incident response.
Backups & Business Continuity Backup, continuity and recovery processes can support resilience and availability of important information.
Secure Information Transfer Protected methods can be used when transmitting sensitive client or consumer information.
Secure Media Disposal Retired storage media can be disposed of through controlled destruction processes designed to prevent data recovery.

Our People & Operating Environment

Information security depends on more than software. Employee practices, access controls, training and documented procedures are also important parts of a strong security environment.

People & Access Controls

Controlled access to systems and sensitive information.
Employee screening and background checks where appropriate.
Confidentiality, privacy and security obligations for staff.
Access based on assigned responsibilities and business need.
Security-awareness and information-handling training.

Workstation & Operational Controls

Managed workstation access and automatic session locking.
Encryption and endpoint protection where appropriate.
Multi-factor authentication for sensitive systems and connectivity.
Monitoring, logging and documented access activity.
Controlled disposal of retired storage media and devices.

Security Frameworks & Standards

ResolveOne can design its security program around recognized cybersecurity, privacy and information-protection principles applicable to the services and information involved in each client program.

01

NIST Cybersecurity Framework

A recognized cybersecurity risk-management framework covering governance, identification, protection, detection, response and recovery.

02

PCI DSS

Payment-card security requirements relevant where cardholder data is handled within the applicable environment and scope.

03

FTC Safeguards Rule

Security principles relevant to covered financial institutions and customer information where the Rule applies.

04

HIPAA / HITECH

Administrative, physical and technical safeguards may apply where protected health information is actually within scope.

References to frameworks or standards describe relevant security principles and potential program requirements. They do not represent a certification or attestation held by ResolveOne unless specifically stated and independently verified.

How We Protect Information

A layered security model can reduce risk by combining multiple technical and operational safeguards rather than relying on any single control.

Authentication

Strong authentication and multi-factor verification can help reduce unauthorized access.

Encryption

Encryption can support protection of information during storage and transmission where appropriate.

Private Connectivity

Secure remote-access and private network controls can help protect sensitive system connections.

Monitoring

Security and system activity can be monitored to support visibility, investigation and response.

Backups & Recovery

Backup and recovery procedures can support business continuity and information availability.

Access Governance

Access can be limited to authorized users based on role, responsibility and legitimate business need.

Compliance Controls & Framework

Compliance and security can be supported through a combination of documented policies, technology, employee training, quality assurance and operational oversight.

Control Area FDCPA Regulation F Policies Technology Training QA
Call-Frequency Controls
Time-of-Day Restrictions
Consumer Preferences & Opt-Outs
Validation & Disputes
Information Security
Recordkeeping & Audit Trails

Security Is a Process. Not a Checkbox.

ResolveOne’s goal is to build security, privacy, compliance and responsible information handling into the way accounts, systems and client programs are managed.