Security
Security whitepaper
How we secure our own systems, our development practice and our customers’ deployments.
Approach
RODMENA is a UK software company specialising in durable, fault-tolerant systems. We apply the same discipline to our own security: encryption in transit for all services, least-privilege access to systems, hardened self-managed infrastructure, and a development practice designed to contain failures and recover from them. We hold minimal personal data, limited to business correspondence, and this website uses no analytics, trackers or advertising cookies.
As a small engineering company we have a limited attack surface, and the people who operate our systems are the people who built them, so accountability is direct. Where a control below is specific to an engagement, its exact form is agreed in the contract documentation.
Identity and access control
- Multi-factor authentication
- Key accounts, including code hosting, infrastructure and email, are protected by MFA and strong, unique credentials in a password manager.
- Least privilege
- Production access is limited to those who need it and is by SSH key, with no password login. Root access is not used day to day.
- Customer systems (RBAC)
- Our software supports role-based access control and multi-tenant isolation, with PostgreSQL row-level security in the products that hold tenant data.
- SSO
- For customer deployments, integration with your identity provider is scoped per engagement.
Encryption
- In transit
- All public services use TLS, and HTTP traffic is redirected to HTTPS.
- At rest
- The managed database fleet runs on encrypted disks, and database backups are encrypted before they leave their host. Some application hosts do not yet encrypt their disks. For customer deployments we recommend and configure encrypted storage and encrypted PostgreSQL backups as standard.
Secure development
- Version control
- All code is held in Git with a reviewable history. Secrets are never committed to repositories.
- Dependencies
- We keep dependencies to a minimum (Highway needs only PostgreSQL, with no Kafka, Redis or external queues) and update them promptly when security advisories are published.
- Testing
- Changes are verified before release, and an automated verification suite checks this website on every change.
Logging, backups and resilience
- Logging
- Server access and error logs are kept for security monitoring and rotated routinely. Logs record operational metadata only, without personal-data payloads.
- Backups
- Engagement systems have scheduled, encrypted and tested backups designed to the agreed recovery objectives. Because Highway is PostgreSQL-native, standard PostgreSQL backup tooling applies.
- Resilience
- Highway uses durable execution. It commits application data and workflow state in the same transaction, so a crash cannot leave partial state.
Vulnerability management
Operating systems and dependencies are patched promptly, in order of severity. We publish a responsible-disclosure policy and a machine-readable security.txt.
Penetration testing: Planned A summary of scope and findings will be published on the Trust Centre after the first engagement.
Incident response and notification
Suspected incidents are triaged immediately by the engineers who operate the affected system. Where an incident affects a customer, we notify that customer without undue delay, setting out what we know, what we are doing and what we recommend. Personal-data breaches are handled in line with UK GDPR, including notification to the ICO within 72 hours where required. Security contact: security@rodmena.co.uk.
Certifications
RODMENA LIMITED is certified under the UK Government-backed Cyber Essentials scheme for the whole organisation: certificate 00d24b59-7739-4d97-bb66-341ac50ef018, valid until 30 September 2027. The current status of Cyber Essentials Plus, ICO registration and ISO/IEC 27001 is kept up to date on the Trust Centre.