Policy for Siccar Software Development
Pynt an scope
This policy describes how RODMENA LIMITED develops software securely — for our ain products (including the Highway workflow engine) and for customer engagements.
Practices
- Version control: aw code bides in Git wi a reviewable history; chynges are made throu commits that can be auditit and revertit.
- Secrets: credentials, keys and tokens are never committed tae repositories; they are stored in appropriate secret storage and rotated when exposure is suspected.
- Dependencies: we keep third-pairty dependencies tae a minimum bi design, pin versions, an update swith when security advisories are furthset.
- Review and testing: changes are tested afore release; failure modes are treatit as design inputs — oor platforms are biggit sae that crashes canna produce pairtial state.
- Least privilege by design: products support role-based access control and tenant isolation (for example row-level security).PostgreSQL
- Data in development: production personal data is no used in development or testing environments.
- Release: deployments are repeatable and reversible; production changes are verified after release.
Vulnerability handling
Vulnerabilities in oor software — fund internally or reportit throu oor responsible-disclosure route — are triaged by severity, fixed promptly, and disclosed responsibly tae affectit customers.
Responsibilities
The Director awns this policy. It is reviewit at least ilka year and whaniver oor toolchain chynges materially.