Trust Centre
Security, privacy an compliance
Buyers an security reviewers can assess RODMENA as a supplier here. Ilka claim shaws its current status.
Security oweriew
RODMENA is a UK software company specialisin in durable, fault-tolerant systems. We apply the same discipline tae oor ain security: encryption in transit fur aw services, least-privilege access tae systems, hardened self-managed infrastructure, an a development practice designed tae contain failures an recover fae them. We haud minimal personal data, limited tae business correspondence, an this website uses nae analytics, trackers or advertising cookies.
Access control, encryption, secure development, backups, vulnerability management an incident response are covered in detail in oor security whitepaper.
Security contact: security@rodmena.co.uk (see forby responsible disclosure an security.txt).
Text messages fae RODMENA
Text messages fae RODMENA’s platforms, includin RODMENA ID an Futex, are sent only fae +44 7822 000922, a nummer dedicatit tae RODMENA’s outbound messages. A text that claims tae come fae RODMENA fae ony ither nummer is no fae us: please report it tae security@rodmena.co.uk. Tae reach us by phone or text, use +44 7537 179434.
Certifications an compliance
| Certification or assessment | Status | Issued | Expires | Evidence |
|---|---|---|---|---|
| Cyber Essentials Certified by GDAK (G-DAK Cyber Solution Ltd); Cyber Essentials Partner IASME (UK Government-backed scheme). Certificate 00d24b59-7739-4d97-bb66-341ac50ef018. Scope: hale organisation. Profile 3.3 (Danzell) | Certified | 2026-09-30 | 2027-09-30 | Register entry |
| Cyber Essentials Plus IASME (UK NCSC scheme). Planned tae follae Cyber Essentials | Plauntit | — | — | — |
| ICO Data Protection Registration Information Commissioner's Office. Registration reference ZC202334 (Tier 1); verifie on the public ICO register | Registered | 2026-07-19 | 2027-07-18 | Register entry Certificate (PDF) |
| ISO/IEC 27001 (Information Security) UKAS-accredited certification body. On the roadmap as the company grows | Plauntit | — | — | — |
| Penetration testing Independent security tester. A summary o scope an findins will be furthset efter the first engagement | Plauntit | — | — | — |
Cyber Essentials
RODMENA LIMITED is certified under the UK Government-backed Cyber Essentials scheme, for the hale organisation.
- Certificate
- 00d24b59-7739-4d97-bb66-341ac50ef018
- Scope
- Hale organisation
- Profile
- 3.3 (Danzell)
- Certified
- 30 September 2026
- Recertification due
- 30 September 2027
- Certification body
- GDAK (G-DAK Cyber Solution Ltd), wi IASME as the Cyber Essentials Partner
- Cyber insurance
- Cyber insurance in place. Evidence available on request from security@rodmena.co.uk.
- Verification
- Public certificate record on the BlockMark registry
The certificate confirms that, when assessed, our ICT defences met the Cyber Essentials requirements against commodity cyber attacks. It is not a guarantee that they will remain satisfactory against every attack.
Insurance
Cyber insurance in place. Evidence available on request from security@rodmena.co.uk. The policy comes wi oor Cyber Essentials certificate an runs fur the same period. Subject tae its terms an limit, it pays fur incident response, the costs o handlin a cyber incident (legal advice, IT forensics, data recovery, noatifeein fowk that's affectit an public relations), loss o income while oor systems ir interruptit, data protection investigations an fines (whaur the law permits), an claims fae third pairties efter a data breach or security failure. It disnae cover money stowlins throu cyber-crime or invoice fraud, an it isnae professional indemnity or public liability cover.
Professional indemnity, public liability an employer’s liability cover is bundit unner ae policy an starts on 1 November 2026. Cover is pit in place tae the leemits a contract requires an evidencet afore signature.
| Kiver | Status | Details |
|---|---|---|
| Professional indemnity | In progress | Bound; cover starts on 1 November 2026 and runs to 31 October 2027. Insurer and limit on request. |
| Public liability | In progress | Boun; cover sterts on 1 November 2026 an rins tae 31 October 2027. Insurer an limit on request. |
| Employer’s liability | In progress | Boun; the cover sterts on 1 November 2026 an rins tae 31 October 2027. Insurer an limit on request. |
| Cyber | In place | Rins tae 30 September 2027, wi the certificate. Insurer an limit on request. |
Privacy an data protection
We haud minimal personal data, limitit tae business correspondence. This wabsteid sets nae cookies an runs nae analytics or trackers. Oor Privacy Policy describes oor processing in detail, an oor Data Processing Agreement page sets oot the Article 28 terms we offer.
DPA requests: legal@rodmena.co.uk · privacy an data-protection questions: privacy@rodmena.co.uk · data-subject requests: gdpr@rodmena.co.uk.
Sub-processors
| Provider | Pörpose | Whaur data is processed |
|---|---|---|
| OVHcloud | Virtual servers fur the production database tier an some application services, an object storage fur encrypted backups | Unitit Kinrick, France and Germany |
| iDNet | Virtual servers fur the wabsteid an application services, an the office connection | Unitit Kinrick |
| Cloud Nord | Servers fur a build runner, alertin an the partner portal | Unitit Kinrick |
| Google Workspace | Staff email, calendars an documents, includin correspondence wi customers | Ireland, Unitit States and ither Google locations |
| Anthropic | Claude Enterprise, the AI assistant RODMENA engineers uise tae operate its systems, that can see operational logs an data | Unitit States |
| GitHub | Source code hostin an continuous integration | Unitit States |
The full register, wi ilka contractin company, the transfer safeguards an the chynges sin 5 October 2026, is on the data processing page. Chynges is annunced at least 30 days ahead in the sub-processor feed.
External services that process nae personal data
RODMENA cmi5 airs its audit chain wi a public RFC 3161 timestamp authority. That service gets a SHA-256 digest o a signed chain heid, aboot ivery fifteen meenits, an only fur a customer whase chain has chynged. Nae personal data, nae identifiers an nae learning records is sent tae it. Whan it cannae be reached, learning, launches, statements an evidence export isnae affected, an anchoring retries on the next pass.
Prism, the model gateway o RODMENA, sends requests tae InferX Technologies, Inc. (Unitit States) fur language-model inference. Nae customer personal data is sent tae it. Afore Prism is uised wi customer personal data, the model will be hostit in the Unitit Kinrick or provydit unner a contract wi transfer safeguards.
Oor domain registrar an DNS provider hauds only domain an zone records.
Responsible disclosure
If ye think ye hae fund a security vulnerability in this wabsteid or in ony RODMENA product, please email security@rodmena.co.uk wi enough detail fur us tae reproduce the issue. We will acknowledge yer report, normally within three workin days, keep ye informed o progress an, if ye wish, credit ye once the issue is resolved.
We will no tak legal action agin guid-faith security resairch that respects user privacy, avoids service disruption an gies us reasonable time tae fix issues afore public disclosure. Oor machine-readable policy is publisht at /.well-known/security.txt.
Service an support
Support comes directly frae the engineers that big our systems. Severity definitions, response expectations an maintenance windaes is descrived on the Service an SLA page. Specific uptime an response targets is agreed per contract.
Severity definitions an the support model are set oot on the Service & SLA page. The exit & portability page describes the exit process. Live service status: the status board on uptime.systems.
Policíes
- Information Security Policy Publish'd
- Policy fur Siccar Software Development Publish'd
- Modren Sclavery Statement Publish'd
- Anti-Bribery & Fraud Policy Publish'd
- Equality & Diversity Policy Publish'd
- Environs Policy Publish'd
- Whistleblowin / Speak-Up Policy Publish'd
- Policie o Conflicts o Interest Publish'd
The policy register wi review dates
Concerns aboot wrang-daein can be raised confidentially throu oor Speak-Up portal, unner the Whistleblowing / Speak-Up Policy.
Mair
- Company information: Companies House details, procurement identifiers, insurance
- Security whitepaper: access control, encryption, secure development, incident response
- Data processing: roles, sub-processors, transfers, retention, breach handling
- Service & SLA: support model, severity definitions, maintenance windows
- Exit & portability: staunart export formats, migration support, deletion certificate
- Social value & carbon reduction: proportionate commitments an oor Carbon Reduction Plan
- Accessibility statement: oor WCAG 2.2 AA commitment an current status
- Privacy Policy: how we handle personal data (UK GDPR / DPA 2018)
- Terms o Service: staunart wabsteid terms