Siccarity
Security whitepaper
Hou we keep oor ain seestems, oor development practice an oor customers' deployments siccar.
Approach
RODMENA is a UK software company specialisin in durable, fault-tolerant systems. We apply the same discipline tae oor ain security: encryption in transit fur aw services, least-privilege access tae systems, hardened self-managed infrastructure, an a development practice designed tae contain failures an recover fae them. We haud minimal personal data, limited tae business correspondence, an this website uses nae analytics, trackers or advertising cookies.
As a wee engineering company we hae a limitit attack surface, an the fowk that operates oor systems is the fowk that biggit them, sae accoontability is direct. Whaur a control ablow is specific tae an engagement, its exact form is agreed in the contract documentation.
Identity an access control
- Multi-factor authentication
- Key accounts, includin code hostin, infrastructure an email, are pertected by MFA an strang, unique credentials in a password manager.
- Least privilege
- Production access is limitit tae thaim that needs it an is by SSH key, wi nae password login. Root access isnae used day tae day.
- Customer systems (RBAC)
- Oor software hauds up role-based access control an multi-tenant isolation, wi PostgreSQL row-level security in the products that haud tenant data.
- SSO
- For customer deployments, integration wi yer identity provider is scoped per engagement.
Encryption
- In transit
- Aa public services uise TLS, an HTTP traffic is redireddit tae HTTPS.
- At rest
- The managed database fleet runs on encrypted disks, and database backups are encrypted before they leave their host. Some application hosts do not yet encrypt their disks. For customer deployments we recommend and configure encrypted storage and encrypted PostgreSQL backups as standard.
Siccar development
- Version control
- Aa code is haudit in Git wi a reviewable history. Secrets is niver committit tae repositories.
- Dependencies
- We keep dependencies tae a minimum (Highway needs only PostgreSQL, wi nae Kafka, Redis or external queues) an update thaim promptly whan security advisories are published.
- Testing
- Chynges ir verifee'd afore release, an a automated verifeecation suite checks this wabsteid on ivery chynge.
Loggin, back-ups an resilience
- Loggin
- Server access an error logs is keepit fur security monitorin an are rowtit reglar. Logs record operational metadata anely, wi nae personal-data payloads.
- Backups
- Engagement systems hae scheduled, encryptit an testit backups designed tae the agreed recovery objectives. Because Highway is PostgreSQL-native, staundart PostgreSQL backup toolin applies.
- Resilience
- Highway uises durable execution. It commits application data an workflow state in the same transaction, sae a crash cannae lea partial state.
Vulnerability management
Operatin systems an dependencies is patched swith, in order o severity. We pit oot a responsible-disclosure policy an a machine-readable security.txt.
Penetration testing: Plauntit A summary o scope an findins will be furthset on the Trust Centre efter the first engagement.
Incident response an notification
Suspected incidents are triaged immediately by the engineers who operate the affected system. Where an incident affects a customer, we notify that customer without undue delay, setting out what we know, what we are doing and what we recommend. Personal-data breaches are handled in line with UK GDPR, including notification to the ICO within 72 hours where required. Security contact: security@rodmena.co.uk.
Certifications
RODMENA LIMITED is certified under the UK Government-backed Cyber Essentials scheme for the hale organisation: certificate 00d24b59-7739-4d97-bb66-341ac50ef018, valid until 30 September 2027. The current status of Cyber Essentials Plus, ICO registration and ISO/IEC 27001 is kept up tae date on the Trust Centre.