Lowp tae content

Hou we rin

We rin the company onwhit we sell.

Oor books, specifications, bill o materials and SBOM, commercial record and email aa run on systems we wrote and operate. Ivry platform we sell runs the company first, sae a release that wud brek a set o books breks oors first.

production databases, ilk ane owned by ae service
22
database hosts
4
countries
3
minutes recovery point on the managed fleet, at maist
5

Comparison

Whit we yaise fur ilka concern

Ilkane o thir records sits on a system we rin, sae we are accoontable whan ane is wrang.

Ilka concern, whit organisations uisually buy in fur it, an the system RODMENA runs
ConcernUsually bocht inWe rin
The booksA subscription o accountsLedger
Specifications an chynge controlA hosted issue trackerTracker
Bill of materials and SBOMA spreadsheet, if onythingProvenance
The commercial record (CRM)A sales subscription, separate frae the accoontsTrace
Documentation an runbooksA documentation subscriptionKnowledge base
Company emailA mail an office subscriptionWebmail

Ilka system abune is biggit, pit oot an rinnin on its ain database. Checkit 2026-09-09.

The systems

The sax systems

Ilk system kivers ae concern, signs fowk in throu oor ain identity service, haes its ain database an exports its data in open formats.

  • The books

    Ledger

    Double-entry accoontin for money, credits an stock. It keeps oor buiks an is the same service we sell.

    Biggit on
    Auth, PostgreSQL
    Data available as
    CSV and JSON

    Opent Ledger Ledger product page

  • Specifications an chynge control

    Tracker

    Ilka chynge tae ilka repository starts wi a scrieven specification an a ticket, an closes wi a note o hou it wus verifee'd.

    Biggit on
    issuedb-cli + EARS, Identity
    Data available as
    JSON, an the ticket database committed in ilka repository

    Opent Tracker

  • Bill of materials and SBOM

    Provenance

    A asset register fur the hardware, an SBOM fur ilka software release we ship, an security findings trackit agin baith.

    Biggit on
    Auth, PostgreSQL
    Data available as
    CycloneDX, SPDX and VEX

    Opent Provenance Provenance product page Sign-in needit

  • The commercial record (CRM)

    Trace

    Customer relationship an revenue records, reckont agin the Ledger.

    Biggit on
    Ledger, Auth
    Data available as
    CSV an JSON

    Opent Trace Trace product page Sign-in needit

  • Documentation an runbooks

    Knowledge base

    Documentation fur ivery platform on the estate, keepit sae that nae service's runbook exists only in the heid o the ane engineer.

    Biggit on
    Auth, TokenGate
    Data available as
    Markdown an JSON

    Opent Knowledge base Sign-in needit

  • Company email

    Webmail

    A mailbox interface ower oor ain mail platform, sae company correspondence bides on infrastructure we operate.

    Biggit on
    RODMENA Mail API, Identity
    Data available as
    IMAP an mbox

    Opent Webmail Sign-in needit

Inby

The Provenance register

Fower screens fae Provenance: the hardware asset register, the evidence pack pit thegither by control reference, the findings table wi VEX positions, an the component explorer.

Fower screens frae the Provenance bill-o-materials platform. An asset register that leets ilka device the company hauds wi its state, custodian an encryption status. An evidence export pack organised by control reference, wi sections fur Cyber Essentials an fur ISO/IEC 27001:2022 Annex A, ilkane statin whit the register evidences an whit it disna. A findings table that leets vulnerabilities by severity wi their CVSS score, the component an release affected, whether that release is deployed, an its VEX assessment. A component explorer that looks a component up across the hale estate by package URL.
Provenance, oor bill-o-materials platform, in uise. We biggit it for the evidence pack: whan a buyer asks whilk components a release hauds an whilk advisories affect thaim, we answer wi an export.

Big or buy

Why we bigg oor ain

For maist o thir seestems, buyin ane in wad mak wee sense.

  • We already sell it

    The ledger that keeps oor books is ane o the products on this site. Payin somebodie else for an equivalent wad be quare, an runnin it oorsels shaws us whit ilka release daes tae a workin set o books.

  • A register for oor ain estate

    A wee supplier cannae subscribe tae a component inventory an security findings across its ain estate in CycloneDX, SPDX an VEX, sae we biggit a register fur it.

  • We uise staunart foonds

    Aa thing abune runs on PostgreSQL, FreeBSD, Python, OpenID Connect an TLS wi public trust. We write the application layer, an we dinnae write oor ain databases, operatin systems or cryptography.

Key-person risk

A company that runs its ain systems has tae cope wi the fowk that biggit them bein unavailable. Ilka repository has its ain runbook. Ilka change has a specification an a ticket recordin how it was verified. Database migrations are stored inside the database they manage, sae they survive a restore. Restores are tested end tae end, an the hale estate is descrived in a published topology.

How we haud it safe How ye lea Trust Centre

Dependencies

Whit ilka system is biggit on

Ilka row shaws a concern, the system that haunles it, an the platforms frae oor ain catalogue that it rins on.

  1. The books

    Ledger

    Auth, PostgreSQL

  2. Specifications an chynge control

    Tracker

    issuedb-cli + EARS, Identity

  3. Bill of materials and SBOM

    Provenance

    Auth, PostgreSQL

  4. The commercial record (CRM)

    Trace

    Ledger, Auth

  5. Documentation an runbooks

    Knowledge base

    Auth, TokenGate

  6. Company email

    Webmail

    RODMENA Mail API, Identity

The richt-han column comes frae oor ain product catalogue. The platforms we sell are the anes we lippen on tae invoice, ship an keep records. See how the platforms fit thegither.

Arrange a walkthrough

We can tak ye throu ony o thae systems, or send the topology, policies an capability statement fur yer procurement pack.