Security
Security whitepaper
Hou we secur oor ain seestems, oor development practice and oor customers' deployments.
Approach
RODMENA is a UK software company specialisin in durable, fault-tolerant systems. We apply the same discipline tae oor ain security: encryption in transit for aw services, least-privilege access tae systems, hardened self-managed infrastructure, and a development practice designed tae contain failures and recover frae them. We haud minimal personal data, limited tae business correspondence, and this website uses nae analytics, trackers or advertising cookies.
As a smaa engineering company we hae a leemitit attack surface, and the fowk that operate oor seestems are the fowk that biggit them, sae accoontability is direct. Whaur a control ablow is specific tae an engagement, its exact form is agreed in the contract documentation.
Identity an access control
- Multi-factor authentication
- Key accoonts, includin code hostin, infrastructure an email, are pertectit bi MFA an strang, unique credentials in a password manager.
- Least privilege
- Production access is limited tae thae fowk that need it and is by SSH key, wi nae password login. Root access isnae used day tae day.
- Customer seestems (RBAC)
- Oor software supports role-based access control and multi-tenant isolation, wi PostgreSQL row-level security in the products that haud tenant data.
- SSO
- For customer deployments, integration wi your identity provider is scoped per engagement.
Encryption
- In transit
- Aw public services uise TLS, an HTTP traffic is redirectit tae HTTPS.
- At rest
- The managed database fleet rins on encryptit disks, and database backups are encryptit afore they leave their host. Some application hosts dae no yet encrypt their disks. For customer deployments we recommend and configure encryptit storage and encryptit PostgreSQL backups as staundart.
Siccar development
- Version control
- Aw code is haudit in Git wi a reviewable history. Secrets are niver committed tae repositories.
- Dependencies
- We keep dependencies tae a minimum (Highway needs only PostgreSQL, wi nae Kafka, Redis or external queues) an update thaim promptly whan security advisories are published.
- Testing
- Chynges are verified afore release, an an automated verification suite checks this wabsteid on ilka chynge.
Loggin, back-ups an resilience
- Loggin
- Server access and error logs are keepit for security monitoring and rotated routinely. Logs record operational metadata anely, wihtout personal-data payloads.
- Backups
- Engagement systems hae scheduled, encrypted an tested backups designed tae the agreed recovery objectives. Because Highway is PostgreSQL-native, staundart PostgreSQL backup toolin applies.
- Grit
- Highway uises durable execution. It commits application data and workflow state in the same transaction, sae a crash cannae leave pairtial state.
Vulnerability management
Operatin systems and dependencies are patched suin, in order o severity. We publish a responsible-disclosure policy and a machine-readable security.txt.
Penetration testing: Pittit doon A summary o scope an findins will be furthset on the Trust Centre efter the first engagement.
Incident response and notification
Suspected incidents are triaged immediately by the engineers who operate the affected system. Where an incident affects a customer, we notify that customer without undue delay, setting out what we know, what we are doing and what we recommend. Personal-data breaches are handled in line with UK GDPR, including notification to the ICO within 72 hours where required. Security contact: security@rodmena.co.uk.
Certifications
RODMENA LIMITED is certified unner the UK Government-backit Cyber Essentials scheme for the hail organisation: certificate 00d24b59-7739-4d97-bb66-341ac50ef018, valid till 30 September 2027. The current status o Cyber Essentials Plus, ICO registration and ISO/IEC 27001 is keepit up tae date on the Trust Centre.