Policy fur Siccar Software Development
Pupose an scope
This policy describes how RODMENA LIMITED develops software securely — for oor ain products (including the Highway workflow engine) and for customer engagements.
Practices
- Version control: aw code bides in Git wi a reviewable history; chynges is made throu commits that can be audited an reverted.
- Secrets: credentials, keys an tokens is niver committed tae repositories; thay ir stored in appropriate secret storage an rotated whan exposure is suspected.
- Dependencies: we keep third-pairty dependencies tae a minimum bi design, pin versions, an update smartly whan security advisories are furthset.
- Review an testin: changes is tested afore release; failure modes is taen as design inputs — oor platforms is biggit sae that crashes cannae produce pairtial state.
- Least privilege by design: products support role-based access control and tenant isolation (for example PostgreSQL row-level security).
- Data in development: production personal data is no used in development or testing environments.
- Release: deployments are repeatable and reversible; production changes are verified after release.
Vulnerability handling
Vulnerabilities in oor software — fund internally or reportit throu oor responsible-disclosure route — are triaged by severity, fixed promptly, an disclosed responsibly tae affected customers.
Responsibilities
The Director awns this policy. It is reviewe't at least ilka year an whaniver oor toolchain chynges materially.