Trust Centre
Security, privacy and compliance
Buyers and security reviewers can assess RODMENA as a supplier here. Each claim shows its current status.
Security overview
RODMENA is a UK software company specialising in durable, fault-tolerant systems. We apply the same discipline to our own security: encryption in transit for all services, least-privilege access to systems, hardened self-managed infrastructure, and a development practice designed to contain failures and recover from them. We hold minimal personal data, limited to business correspondence, and this website uses no analytics, trackers or advertising cookies.
Access control, encryption, secure development, backups, vulnerability management and incident response are covered in detail in our security whitepaper.
Security contact: security@rodmena.co.uk (see also responsible disclosure and security.txt).
Text messages from RODMENA
Text messages from RODMENA’s platforms, including RODMENA ID and Futex, are sent only from +44 7822 000922, a number dedicated to RODMENA’s outbound messages. A text that claims to come from RODMENA from any other number is not from us: please report it to security@rodmena.co.uk. To reach us by phone or text, use +44 7537 179434.
Certifications and compliance
| Certification or assessment | Status | Issued | Expires | Evidence |
|---|---|---|---|---|
| Cyber Essentials Certified by GDAK (G-DAK Cyber Solution Ltd); Cyber Essentials Partner IASME (UK Government-backed scheme). Certificate 00d24b59-7739-4d97-bb66-341ac50ef018. Scope: whole organisation. Profile 3.3 (Danzell) | Certified | 2026-09-30 | 2027-09-30 | Register entry |
| Cyber Essentials Plus IASME (UK NCSC scheme). Planned to follow Cyber Essentials | Planned | — | — | — |
| ICO Data Protection Registration Information Commissioner's Office. Registration reference ZC202334 (Tier 1); verify on the public ICO register | Registered | 2026-07-19 | 2027-07-18 | Register entry Certificate (PDF) |
| ISO/IEC 27001 (Information Security) UKAS-accredited certification body. On the roadmap as the company grows | Planned | — | — | — |
| Penetration testing Independent security tester. A summary of scope and findings will be published after the first engagement | Planned | — | — | — |
Cyber Essentials
RODMENA LIMITED is certified under the UK Government-backed Cyber Essentials scheme, for the whole organisation.
- Certificate
- 00d24b59-7739-4d97-bb66-341ac50ef018
- Scope
- Whole organisation
- Profile
- 3.3 (Danzell)
- Certified
- 30 September 2026
- Recertification due
- 30 September 2027
- Certification body
- GDAK (G-DAK Cyber Solution Ltd), with IASME as the Cyber Essentials Partner
- Cyber insurance
- Cyber insurance in place. Evidence available on request from security@rodmena.co.uk.
- Verification
- Public certificate record on the BlockMark registry
The certificate confirms that, when assessed, our ICT defences met the Cyber Essentials requirements against commodity cyber attacks. It is not a guarantee that they will remain satisfactory against every attack.
Insurance
Cyber insurance in place. Evidence available on request from security@rodmena.co.uk. The policy comes with our Cyber Essentials certificate and runs for the same period. Subject to its terms and limit, it pays for incident response, the costs of handling a cyber incident (legal advice, IT forensics, data recovery, notifying affected people and public relations), loss of income while our systems are interrupted, data protection investigations and fines (where the law permits), and claims from third parties after a data breach or security failure. It does not cover money stolen through cyber-crime or invoice fraud, and it is not professional indemnity or public liability cover.
Professional indemnity, public liability and employer’s liability cover is bound under one policy and starts on 1 November 2026. Cover is placed to the limits a contract requires and evidenced before signature.
| Cover | Status | Details |
|---|---|---|
| Professional indemnity | In progress | Bound; cover starts on 1 November 2026 and runs to 31 October 2027. Insurer and limit on request. |
| Public liability | In progress | Bound; cover starts on 1 November 2026 and runs to 31 October 2027. Insurer and limit on request. |
| Employer’s liability | In progress | Bound; cover starts on 1 November 2026 and runs to 31 October 2027. Insurer and limit on request. |
| Cyber | In place | Runs to 30 September 2027, with the certificate. Insurer and limit on request. |
Privacy and data protection
We hold minimal personal data, limited to business correspondence. This website sets no cookies and runs no analytics or trackers. Our Privacy Policy describes our processing in detail, and our Data Processing Agreement page sets out the Article 28 terms we offer.
DPA requests: legal@rodmena.co.uk · privacy and data-protection questions: privacy@rodmena.co.uk · data-subject requests: gdpr@rodmena.co.uk.
Sub-processors
| Provider | Purpose | Where data is processed |
|---|---|---|
| OVHcloud | Virtual servers for the production database tier and some application services, and object storage for encrypted backups | United Kingdom, France and Germany |
| iDNet | Virtual servers for the website and application services, and the office connection | United Kingdom |
| Cloud Nord | Servers for a build runner, alerting and the partner portal | United Kingdom |
| Google Workspace | Staff email, calendars and documents, including correspondence with customers | Ireland, United States and other Google locations |
| Anthropic | Claude Enterprise, the AI assistant RODMENA engineers use to operate its systems, which can see operational logs and data | United States |
| GitHub | Source code hosting and continuous integration | United States |
The full register, with each contracting company, the transfer safeguards and the changes since 5 October 2026, is on the data processing page. Changes are announced at least 30 days ahead in the sub-processor feed.
External services that process no personal data
RODMENA cmi5 anchors its audit chain with a public RFC 3161 timestamp authority. That service receives a SHA-256 digest of a signed chain head, about every fifteen minutes, and only for a customer whose chain has changed. No personal data, no identifiers and no learning records are sent to it. When it cannot be reached, learning, launches, statements and evidence export are unaffected, and anchoring retries on the next pass.
Prism, RODMENA’s model gateway, sends requests to InferX Technologies, Inc. (United States) for language-model inference. No customer personal data is sent to it. Before Prism is used with customer personal data, the model will be hosted in the United Kingdom or provided under a contract with transfer safeguards.
Our domain registrar and DNS provider holds only domain and zone records.
Responsible disclosure
If you believe you have found a security vulnerability in this website or in any RODMENA product, please email security@rodmena.co.uk with enough detail for us to reproduce the issue. We will acknowledge your report, normally within three working days, keep you informed of progress and, if you wish, credit you once the issue is resolved.
We will not take legal action against good-faith security research that respects user privacy, avoids service disruption and gives us reasonable time to fix issues before public disclosure. Our machine-readable policy is published at /.well-known/security.txt.
Service and support
Support comes directly from the engineers who build our systems. Severity definitions, response expectations and maintenance windows are described on the Service and SLA page. Specific uptime and response targets are agreed per contract.
Severity definitions and the support model are set out on the Service & SLA page. The exit & portability page describes the exit process. Live service status: the status board on uptime.systems.
Policies
- Information Security Policy Published
- Secure Software Development Policy Published
- Modern Slavery Statement Published
- Anti-Bribery & Fraud Policy Published
- Equality & Diversity Policy Published
- Environmental Policy Published
- Whistleblowing / Speak-Up Policy Published
- Conflicts of Interest Policy Published
The policy register with review dates
Concerns about wrongdoing can be raised confidentially through our Speak-Up portal, under the Whistleblowing / Speak-Up Policy.
More
- Company information: Companies House details, procurement identifiers, insurance
- Security whitepaper: access control, encryption, secure development, incident response
- Data processing: roles, sub-processors, transfers, retention, breach handling
- Service & SLA: support model, severity definitions, maintenance windows
- Exit & portability: standard export formats, migration support, deletion certificate
- Social value & carbon reduction: proportionate commitments and our Carbon Reduction Plan
- Accessibility statement: our WCAG 2.2 AA commitment and current status
- Privacy Policy: how we handle personal data (UK GDPR / DPA 2018)
- Terms of Service: standard website terms