Lowp tae content

Trust Centre

Security, privacy and compliance

Buyers and security reviewers can assess RODMENA as a supplier here. Ilka claim shaws its current status.

A note on status. RODMENA is a young company (incorporated May 2025) and is building its assurance portfolio. Each certification below is shown as held, in progress or planned, and we update this page when a status changes.

Security oweriew

RODMENA is a UK software company specialisin in durable, fault-tolerant systems. We apply the same discipline tae oor ain security: encryption in transit for aw services, least-privilege access tae systems, hardened self-managed infrastructure, and a development practice designed tae contain failures and recover frae them. We haud minimal personal data, limited tae business correspondence, and this website uses nae analytics, trackers or advertising cookies.

Access control, encryption, secure development, backups, vulnerability management and incident response are covered in detail in our security whitepaper.

Security contact: security@rodmena.co.uk (see forby responsible disclosure and security.txt).

Text messages frae RODMENA

Text messages frae RODMENA’s platforms, includin RODMENA ID and Futex, are sent anely frae +44 7822 000922, a nummer dedicatit tae RODMENA’s outbound messages. A text that claims tae come frae RODMENA frae ony ither nummer is no frae us: please report it tae security@rodmena.co.uk. Tae reach us by phone or text, use +44 7537 179434.

Certifications and compliance

Certifications, assessments and their current status
Certification or assessmentStatusIssuedExpiresEvidence
Cyber Essentials
Certifee'd by GDAK (G-DAK Cyber Solution Ltd); Cyber Essentials Partner IASME (UK Government-backit scheme). Certificate 00d24b59-7739-4d97-bb66-341ac50ef018. Scope: hale organisation. Profile 3.3 (Danzell)
Certifee'd2026-09-302027-09-30Register entry
Cyber Essentials Plus
IASME (UK NCSC scheme). Planned tae follae Cyber Essentials
Pittit doon———
ICO Data Protection Registration
Information Commissioner's Office. Registration reference ZC202334 (Tier 1); verifie on the public ICO register
Registert2026-07-192027-07-18Register entry Certificate (PDF)
ISO/IEC 27001 (Information Security)
UKAS-accredited certification body. On the roadmap as the company grows
Pittit doon———
Penetration testing
Independent security tester. A summary o scope and findins will be furthset efter the first engagement
Pittit doon———
Cyber Essentials certified: verifie the certificate o RODMENA LIMITED on the BlockMark registry

Cyber Essentials

RODMENA LIMITED is certified unner the UK Government-backit Cyber Essentials scheme, for the hail organisation.

Certificate
00d24b59-7739-4d97-bb66-341ac50ef018
Scope
Hale organisation
Profile
3.3 (Danzell)
Certifee'd
30 September 2026
Recertification due
30 September 2027
Certification body
GDAK (G-DAK Cyber Solution Ltd), wi IASME as the Cyber Essentials Partner
Cyber insurance
Cyber insurance in place. Evidence available on request from security@rodmena.co.uk.

The certificate confirms that, when assessed, our ICT defences met the Cyber Essentials requirements against commodity cyber attacks. It is not a guarantee that they will remain satisfactory against every attack.

Insurance

Cyber insurance in place. Evidence available on request from security@rodmena.co.uk. The policy comes wi oor Cyber Essentials certificate and rins for the same period. Subject tae its terms and limit, it pays for incident response, the costs o haundlin a cyber incident (legal advice, IT forensics, data recovery, notifeein fowk that's affectit and public relations), loss o income while oor systems are interruptit, data protection investigations and fines (whaur the law permits), and claims fae third pairties efter a data breach or security failure. It disna cover money stown throu cyber-crime or invoice fraud, and it isna professional indemnity or public liability cover.

Professional indemnity, public liability and employer’s liability cover is bound under one policy and starts on 1 November 2026. The cover is pit in place tae the leemits a contract requires and evidenced afore signature.

Insurance policies and thair current status
CoverStatusDetails
Professional indemnityIn progressBindit; the cover stairts on 1 November 2026 and rins tae 31 October 2027. Insurer and limit on request.
Public liabilityIn progressBindit; the cover stairts on 1 November 2026 and rins tae 31 October 2027. Insurer and limit on request.
Employer’s liabilityIn progressBindit; the cover stairts on 1 November 2026 and rins tae 31 October 2027. Insurer and limit on request.
CyberIn placeRins tae 30 September 2027, wi the certificate. Insurer and limit on request.

Privacy an data protection

We haud minimal personal data, limited tae business correspondence. This wabsteid sets nae cookies an runs nae analytics or trackers. Oor Privacy Policy describes oor processing in detail, an oor Data Processing Agreement page sets oot the Article 28 terms we offer.

DPA requests: legal@rodmena.co.uk · privacy and data-protection questions: privacy@rodmena.co.uk · data-subject requests: gdpr@rodmena.co.uk.

Sub-processors

Sub-processors, thair purpose and whaur thay process data
ProviderPuposeWhaur data is prucessed
OVHcloudVirtual servers for the production database tier and some application services, and object storage for encrypted backupsUnitit Kinrick, France and Germany
iDNetVirtual servers for the wabsteid and application services, and the office connectionUnitit Kinrick
Cloud NordServers for a build runner, alertin an the partner portalUnitit Kinrick
Google WorkspaceStaff email, calendars and documents, includin correspondence wi customersIreland, Unitit States and ither Google locations
AnthropicClaude Enterprise, the AI assistant RODMENA engineers uise tae operate its systems, that can see operational logs and dataUnitit States
GitHubHostin o source code an continuous integrationUnitit States

The full register, wi ilka contracting company, the transfer safeguards and the chynges syne 5 October 2026, is on the data processing page. Chynges are annoonced at least 30 days ahead in the sub-processor feed.

External services that process nae personal data

RODMENA cmi5 airtins its audit chain wi a public RFC 3161 timestamp authority. That service gets a SHA-256 digest o a signed chain heid, aboot ilka fifteen meenits, and only for a customer whase chain has chynged. Nae personal data, nae identifiers and nae learning records are sent tae it. Whan it canna be reached, learning, launches, statements and evidence export are no affected, and anchoring retries on the next pass.

Prism, the model gateway o RODMENA, sends requests tae InferX Technologies, Inc. (Unitit States) for language-model inference. Nae customer personal data is sent tae it. Afore Prism is uised wi customer personal data, the model will be hostit in the Unitit Kinrick or providit unner a contract wi transfer safeguards.

Oor domain registrar an DNS provider hauds only domain an zone records.

Responsible disclosure

If ye believe ye hae fund a security vulnerability in this wabsteid or in ony RODMENA product, please email security@rodmena.co.uk wi enough detail for us tae reproduce the issue. We will acknowledge yer report, normally within three workin days, keep ye informed o progress and, if ye wish, credit ye ance the issue is resolved.

We will no tak legal action agin guid-faith security resairch that respects user privacy, avoids service disruption and gies us reasonable time tae fix issues afore public disclosure. Our machine-readable policy is published at /.well-known/security.txt.

Service and support

Support comes straucht frae the engineers that big oor systems. Severity definitions, response expectations and maintenance windaes are descrived on the Service and SLA page. Specific uptime and response targets are agreed per contract.

Severity definitions and the support model are set out on the Service & SLA page. The exit & portability page describes the exit process. Live service status: the status board on uptime.systems.

Policíes

The policy register wi review dates

Concerns aboot wrongdoing can be raised confidentially throu oor Speak-Up portal, under the Whistleblowing / Speak-Up Policy.

Mair