Information Security Policy

RODMENA LIMITED (company no. 16472788) · Owner: Farshid Ashouri, Director · Adopted: 19 July 2026 · Reviewed at least annually

Purpose and scope

This policy sets out how RODMENA LIMITED protects the confidentiality, integrity and availability of information — our own, and information entrusted to us by customers. It applies to everyone who works for or with the company, and to all systems we operate. It is deliberately proportionate to a small specialist supplier: few controls, applied rigorously, rather than many applied on paper.

Commitments

  • Information is classified by sensitivity and handled accordingly; customer data is always treated as confidential.
  • Access to systems and data follows least privilege and is reviewed when roles or engagements change.
  • Key accounts (code hosting, infrastructure, email) use multi-factor authentication and strong unique credentials in a password manager.
  • All services use encryption in transit (TLS); portable devices use full-disk encryption.
  • Operating systems and dependencies are patched promptly, prioritised by severity.
  • We hold the minimum personal data needed to operate (see our Privacy Policy) and follow UK GDPR.
  • Security incidents are triaged immediately, contained, documented, and reported to affected parties without undue delay (see security whitepaper).
  • Backups for engagement systems are scheduled, encrypted and tested against agreed recovery objectives.

Responsibilities

The Director owns this policy, its implementation and its review. Anyone engaged by the company must follow it and report suspected weaknesses or incidents at once to enquiries@rodmena.co.uk — reporting in good faith will never be penalised.

Certification alignment

Our control set is being aligned with the Cyber Essentials scheme; live certification statuses are published on the Trust Centre.