Trust Centre
Security, privacy and compliance
Buyers and security reviewers can assess RODMENA as a supplier here. Ilka claim shaws its current status.
Security oweriew
RODMENA is a UK software company specialisin in durable, fault-tolerant systems. We apply the same discipline tae oor ain security: encryption in transit for aw services, least-privilege access tae systems, hardened self-managed infrastructure, and a development practice designed tae contain failures and recover frae them. We haud minimal personal data, limited tae business correspondence, and this website uses nae analytics, trackers or advertising cookies.
Access control, encryption, secure development, backups, vulnerability management and incident response are covered in detail in our security whitepaper.
Security contact: security@rodmena.co.uk (see forby responsible disclosure and security.txt).
Text messages frae RODMENA
Text messages frae RODMENA’s platforms, includin RODMENA ID and Futex, are sent anely frae +44 7822 000922, a nummer dedicatit tae RODMENA’s outbound messages. A text that claims tae come frae RODMENA frae ony ither nummer is no frae us: please report it tae security@rodmena.co.uk. Tae reach us by phone or text, use +44 7537 179434.
Certifications and compliance
| Certification or assessment | Status | Issued | Expires | Evidence |
|---|---|---|---|---|
| Cyber Essentials Certifee'd by GDAK (G-DAK Cyber Solution Ltd); Cyber Essentials Partner IASME (UK Government-backit scheme). Certificate 00d24b59-7739-4d97-bb66-341ac50ef018. Scope: hale organisation. Profile 3.3 (Danzell) | Certifee'd | 2026-09-30 | 2027-09-30 | Register entry |
| Cyber Essentials Plus IASME (UK NCSC scheme). Planned tae follae Cyber Essentials | Pittit doon | — | — | — |
| ICO Data Protection Registration Information Commissioner's Office. Registration reference ZC202334 (Tier 1); verifie on the public ICO register | Registert | 2026-07-19 | 2027-07-18 | Register entry Certificate (PDF) |
| ISO/IEC 27001 (Information Security) UKAS-accredited certification body. On the roadmap as the company grows | Pittit doon | — | — | — |
| Penetration testing Independent security tester. A summary o scope and findins will be furthset efter the first engagement | Pittit doon | — | — | — |
Cyber Essentials
RODMENA LIMITED is certified unner the UK Government-backit Cyber Essentials scheme, for the hail organisation.
- Certificate
- 00d24b59-7739-4d97-bb66-341ac50ef018
- Scope
- Hale organisation
- Profile
- 3.3 (Danzell)
- Certifee'd
- 30 September 2026
- Recertification due
- 30 September 2027
- Certification body
- GDAK (G-DAK Cyber Solution Ltd), wi IASME as the Cyber Essentials Partner
- Cyber insurance
- Cyber insurance in place. Evidence available on request from security@rodmena.co.uk.
- Verification
- Public certificate record on the BlockMark registry
The certificate confirms that, when assessed, our ICT defences met the Cyber Essentials requirements against commodity cyber attacks. It is not a guarantee that they will remain satisfactory against every attack.
Insurance
Cyber insurance in place. Evidence available on request from security@rodmena.co.uk. The policy comes wi oor Cyber Essentials certificate and rins for the same period. Subject tae its terms and limit, it pays for incident response, the costs o haundlin a cyber incident (legal advice, IT forensics, data recovery, notifeein fowk that's affectit and public relations), loss o income while oor systems are interruptit, data protection investigations and fines (whaur the law permits), and claims fae third pairties efter a data breach or security failure. It disna cover money stown throu cyber-crime or invoice fraud, and it isna professional indemnity or public liability cover.
Professional indemnity, public liability and employer’s liability cover is bound under one policy and starts on 1 November 2026. The cover is pit in place tae the leemits a contract requires and evidenced afore signature.
| Cover | Status | Details |
|---|---|---|
| Professional indemnity | In progress | Bindit; the cover stairts on 1 November 2026 and rins tae 31 October 2027. Insurer and limit on request. |
| Public liability | In progress | Bindit; the cover stairts on 1 November 2026 and rins tae 31 October 2027. Insurer and limit on request. |
| Employer’s liability | In progress | Bindit; the cover stairts on 1 November 2026 and rins tae 31 October 2027. Insurer and limit on request. |
| Cyber | In place | Rins tae 30 September 2027, wi the certificate. Insurer and limit on request. |
Privacy an data protection
We haud minimal personal data, limited tae business correspondence. This wabsteid sets nae cookies an runs nae analytics or trackers. Oor Privacy Policy describes oor processing in detail, an oor Data Processing Agreement page sets oot the Article 28 terms we offer.
DPA requests: legal@rodmena.co.uk · privacy and data-protection questions: privacy@rodmena.co.uk · data-subject requests: gdpr@rodmena.co.uk.
Sub-processors
| Provider | Pupose | Whaur data is prucessed |
|---|---|---|
| OVHcloud | Virtual servers for the production database tier and some application services, and object storage for encrypted backups | Unitit Kinrick, France and Germany |
| iDNet | Virtual servers for the wabsteid and application services, and the office connection | Unitit Kinrick |
| Cloud Nord | Servers for a build runner, alertin an the partner portal | Unitit Kinrick |
| Google Workspace | Staff email, calendars and documents, includin correspondence wi customers | Ireland, Unitit States and ither Google locations |
| Anthropic | Claude Enterprise, the AI assistant RODMENA engineers uise tae operate its systems, that can see operational logs and data | Unitit States |
| GitHub | Hostin o source code an continuous integration | Unitit States |
The full register, wi ilka contracting company, the transfer safeguards and the chynges syne 5 October 2026, is on the data processing page. Chynges are annoonced at least 30 days ahead in the sub-processor feed.
External services that process nae personal data
RODMENA cmi5 airtins its audit chain wi a public RFC 3161 timestamp authority. That service gets a SHA-256 digest o a signed chain heid, aboot ilka fifteen meenits, and only for a customer whase chain has chynged. Nae personal data, nae identifiers and nae learning records are sent tae it. Whan it canna be reached, learning, launches, statements and evidence export are no affected, and anchoring retries on the next pass.
Prism, the model gateway o RODMENA, sends requests tae InferX Technologies, Inc. (Unitit States) for language-model inference. Nae customer personal data is sent tae it. Afore Prism is uised wi customer personal data, the model will be hostit in the Unitit Kinrick or providit unner a contract wi transfer safeguards.
Oor domain registrar an DNS provider hauds only domain an zone records.
Responsible disclosure
If ye believe ye hae fund a security vulnerability in this wabsteid or in ony RODMENA product, please email security@rodmena.co.uk wi enough detail for us tae reproduce the issue. We will acknowledge yer report, normally within three workin days, keep ye informed o progress and, if ye wish, credit ye ance the issue is resolved.
We will no tak legal action agin guid-faith security resairch that respects user privacy, avoids service disruption and gies us reasonable time tae fix issues afore public disclosure. Our machine-readable policy is published at /.well-known/security.txt.
Service and support
Support comes straucht frae the engineers that big oor systems. Severity definitions, response expectations and maintenance windaes are descrived on the Service and SLA page. Specific uptime and response targets are agreed per contract.
Severity definitions and the support model are set out on the Service & SLA page. The exit & portability page describes the exit process. Live service status: the status board on uptime.systems.
Policíes
- Information Security Policy Publishit
- Policy for Siccar Software Development Publishit
- Modren Sclavery Statement Publishit
- Anti-Bribery & Fraud Policy Publishit
- Equality & Diversity Policy Publishit
- Environment Policy Publishit
- Whistleblowing / Speak-Up Policy Publishit
- Policie on Conflicts o Interest Publishit
The policy register wi review dates
Concerns aboot wrongdoing can be raised confidentially throu oor Speak-Up portal, under the Whistleblowing / Speak-Up Policy.
Mair
- Company information: Companies House details, procurement identifiers, insurance
- Security whitepaper: access control, encryption, secure development, incident response
- Data processing: roles, sub-processors, transfers, retention, breach handling
- Service & SLA: support model, severity definitions, maintenance windaes
- Exit & portability: staundart export formats, migration support, deletion certificate
- Social value & carbon reduction: proportionate commitments and oor Carbon Reduction Plan
- Accessibility statement: oor WCAG 2.2 AA commitment and current status
- Privacy Policy: hou we haundle personal data (UK GDPR / DPA 2018)
- Terms o Service: staundart wabsteid terms