Learning delivery
RODMENA cmi5
Coming soonThe launching system that makes cmi5 courses behave the way the standard says.
RODMENA cmi5 is the LMS side of the cmi5 standard. It imports cmi5 course packages, registers learners, and launches each part of a course with a single-use link. It checks every learning record a course sends against the cmi5 rules before accepting it, then decides completion and satisfaction by the course’s own criteria. Records are kept and forwarded in order to the RODMENA LRS, so learning continues even when the LRS is unavailable.
Who it is for. Organisations and learning platforms that deliver cmi5 courses, including public-sector buyers who need learning records they can audit. It is used through its API by a learning management system, and learners never call it directly. REES is its first consumer.
- Status
- Coming soon
- Part of
- Offerings
- Licence
- Proprietary. Copyright RODMENA LIMITED, all rights reserved.
- Conformance
- 21 cmi5 package tests, all passed
- 66 cmi5 runtime tests, all passed
- Verified 24 September 2026
- Tags
- cmi5xAPIe-learningCourse launchLMS integrationLearning records
Technical specification
Stated for a technical assessor. A row with no measured value is left out.
Standards
- cmi5
- cmi5 (Quartz), with xAPI 1.0.3 as the statement format.
- Conformance suite
- ADL CATAPULT LMS test suite, run in headless Chrome against the running system.
- Conformance result
- Package tests: 21 of 21. Runtime tests: 66 of 66.
- Repeatability
- Both suites were run four times in a single day against the running system, and all four runs were identical.
- System of record
- The RODMENA LRS. cmi5 forwards every accepted record to it.
Course lifecycle
- Import
- cmi5 course packages are imported and their structure read from the manifest.
- Launch
- Each assignable unit is launched with a single-use link, so a link cannot be replayed or shared into a second session.
- Rules at the door
- Every statement a course sends is checked against the cmi5 session and verb rules before it is accepted. A refusal names the specification requirement it breaks.
- Completion
- Completion and satisfaction are decided by the course’s own criteria, as the standard requires, and not by a rule of ours.
- Return
- Where the learning management system supplies a return URL, the learner is offered a way back to it.
Durability
- Through an LRS outage
- Records are accepted and held while the LRS is unavailable, then forwarded when it returns. Learning continues meanwhile.
- Exactly once, in order
- Held records are forwarded exactly once and in order, and ordering holds across forwarded batches.
- Measured
- A ten-minute LRS outage with 200 learners produced no learner-facing errors. Delivery of every held record was checked afterwards against what cmi5 had accepted.
Isolation and security
- Tenant isolation
- Each customer’s data is separated by rules the database enforces, and not by application code alone.
- Encryption at rest
- AES-256-GCM, with keys bound to the row they protect.
- Learner identifiers
- The identifier the learning management system supplies is an xAPI account of home page and name. Email-style identifiers are refused. It is stored only as a keyed token.
- Client addresses
- Never stored. Request logs carry a keyed token in place of an IP address.
- Stored objects
- Course packages and erasure records are encrypted on our host before they are uploaded to object storage.
Data protection
- Role
- A processor, acting for the learning management system customer as controller. Article 28 terms are on the Data Processing Agreement page.
- What is processed
- The learner identifier the customer’s system supplies, and the learning records a course sends, including results and scores.
- Retention
- Per tenant and contractual. The defaults are 1,095 days for registrations and statement bodies, configurable down to one day.
- Erasure
- A learner’s records are pseudonymised in cmi5 immediately, their document copies in the LRS are stopped and removed, and the erasure is handed to the RODMENA LRS with a recorded receipt, so one request reaches both systems. After a database restore, every erasure is re-applied from sealed records kept outside the database, as a step of the restore procedure.
- Operator reasons
- The reason recorded for an erasure or a deletion is a ticket reference or a code, never free text about a person, because those records outlive the data.
- Location
- The same database tier the Trust Centre states, in the United Kingdom, France and Germany, with no other transfer.
Integrations
- Document copies to the LRS
- Optional and off by default, per customer. Saved-state and learner-preference documents are copied one way to the RODMENA LRS and deleted there when they are deleted or reach retention. Session launch data is copied without its entitlement key.
- LRS cross-check
- On request, a registration’s statements are compared with the LRS copy, and a signed result for each statement is added to the evidence pack.
- Signed statements
- Optional, per customer. The statements cmi5 writes itself (launched, abandoned, satisfied, waived) carry an xAPI digital signature with RODMENA’s service certificate. The signature is removed with the statement body at retention or erasure.
- Webhooks
- Optional. Event notifications go to HTTPS endpoints the customer registers, signed with HMAC-SHA256. They carry only ids the customer already holds and timestamps, never a learner identifier or a learning record. Events are kept for 30 days.
Exit and portability
- Return of data
- A customer requests an export through the API. It runs only after a second person approves it, is encrypted to the customer’s own key, and comes with a signed manifest covering every table the customer owns.
- Deletion at contract end
- Every record and every stored object version is removed. The customer receives a signed, timestamped deletion certificate listing what was deleted, what is kept and why, and what it does not cover.
Evidence
- Completion evidence
- Exported as a signed, timestamped pack that a third party can verify offline, without access to our systems.
- Timestamping
- A public RFC 3161 timestamp authority anchors the audit chain. It receives a SHA-256 digest of a signed chain head, about every fifteen minutes, and only for a customer whose chain has changed. No personal data, no identifiers and no statements are sent to it.
- If the authority is unreachable
- Learning, launches, statements and evidence export are unaffected. Anchoring retries on the next pass, the newest audit rows are simply not yet covered by an anchor, and each tenant’s health reports how long they have waited.
Accessibility
Partially conformant with WCAG 2.2 AA. Our surfaces meet WCAG 2.2 AA so that a public-sector customer can meet its duty under the Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018. The Equality Act 2010 binds RODMENA directly.
This product
- What this covers
- The four pages a learner sees: the launch page; the app launch page (“Open your course in its app”), shown instead when a course opens in a separate app on the learner’s device, which never opens anything by itself and always waits for Continue; the page shown when a link has expired or has already been used; and the error page. Course content itself belongs to the customer and is outside this statement.
- Automated testing
- axe-core 4, WCAG 2.2 AA plus its best-practice rules: 20 checks clean out of 20, covering five page forms (launch, app launch, expired with and without a way back, error) at desktop and phone widths in both the light and the dark theme, run against the live pages on 26 September 2026.
- Screen reader
- Tested with Orca 46 and Google Chrome on Linux on every page. Each page is announced with its title or main landmark, and the single control as “Continue push button” or “Return to the course page link”.
- Keyboard
- Tested by keyboard alone in Google Chrome on macOS and Linux. The first Tab reaches the only control on each page, with a visible 3 px focus state. On macOS, Chrome and Safari skip links on Tab unless “Press Tab to highlight each item” is on; Option+Tab reaches them either way.
- Without JavaScript
- The launch page submits on its own where scripting is available, and a visible Continue button is the path where it is not. Nothing on these pages requires a script.
- No time limits
- No countdown and no time limit is presented to the learner on any of the pages.
- Built from
- Plain semantic HTML with one main landmark, a single-column layout and a polite live region for status. No third-party user-interface framework is used.
- Not yet done
- Testing with VoiceOver, NVDA or JAWS, and TalkBack, and a third-party accessibility audit. Until the audit is complete the statement stays at partially conformant, and we will say so to any buyer who asks.
- Reporting a problem
- Accessibility problems with these pages go to the address on our accessibility statement, and we answer them there.
What it does
-
Conformance-tested
Passes the ADL CATAPULT cmi5 LMS test suite: 21 of 21 package tests and 66 of 66 runtime tests.
-
Rules enforced at the door
Every statement a course sends is checked against the cmi5 session and verb rules, and a refusal names the requirement it breaks.
-
Keeps working through an outage
Records are accepted and held, then forwarded exactly once and in order. A ten-minute LRS outage with 200 learners caused no learner-facing errors.
-
Isolated and encrypted
Each customer’s data is separated by database row-level security, encrypted at rest, and learner identifiers are stored only as keyed tokens.
-
Evidence a third party can check
Completion evidence is exported as a signed, timestamped pack that verifies offline without access to our systems.
-
Erasure that reaches the LRS
A learner’s erasure is applied immediately in cmi5 and handed to the LRS with a recorded receipt.
For documentation, a pilot or an integration, contact us.