Skip to content

Learning delivery

RODMENA cmi5

Coming soon

The launching system that makes cmi5 courses behave the way the standard says.

RODMENA cmi5 is the LMS side of the cmi5 standard. It imports cmi5 course packages, registers learners, and launches each part of a course with a single-use link. It checks every learning record a course sends against the cmi5 rules before accepting it, then decides completion and satisfaction by the course’s own criteria. Records are kept and forwarded in order to the RODMENA LRS, so learning continues even when the LRS is unavailable.

Who it is for. Organisations and learning platforms that deliver cmi5 courses, including public-sector buyers who need learning records they can audit. It is used through its API by a learning management system, and learners never call it directly. REES is its first consumer.

Status
Coming soon
Part of
Offerings
Licence
Proprietary. Copyright RODMENA LIMITED, all rights reserved.
Conformance
21 cmi5 package tests, all passed
66 cmi5 runtime tests, all passed
Verified 24 September 2026
Tags
cmi5xAPIe-learningCourse launchLMS integrationLearning records

Technical specification

Stated for a technical assessor. A row with no measured value is left out.

Standards

cmi5
cmi5 (Quartz), with xAPI 1.0.3 as the statement format.
Conformance suite
ADL CATAPULT LMS test suite, run in headless Chrome against the running system.
Conformance result
Package tests: 21 of 21. Runtime tests: 66 of 66.
Repeatability
Both suites were run four times in a single day against the running system, and all four runs were identical.
System of record
The RODMENA LRS. cmi5 forwards every accepted record to it.

Course lifecycle

Import
cmi5 course packages are imported and their structure read from the manifest.
Launch
Each assignable unit is launched with a single-use link, so a link cannot be replayed or shared into a second session.
Rules at the door
Every statement a course sends is checked against the cmi5 session and verb rules before it is accepted. A refusal names the specification requirement it breaks.
Completion
Completion and satisfaction are decided by the course’s own criteria, as the standard requires, and not by a rule of ours.
Return
Where the learning management system supplies a return URL, the learner is offered a way back to it.

Durability

Through an LRS outage
Records are accepted and held while the LRS is unavailable, then forwarded when it returns. Learning continues meanwhile.
Exactly once, in order
Held records are forwarded exactly once and in order, and ordering holds across forwarded batches.
Measured
A ten-minute LRS outage with 200 learners produced no learner-facing errors. Delivery of every held record was checked afterwards against what cmi5 had accepted.

Isolation and security

Tenant isolation
Each customer’s data is separated by rules the database enforces, and not by application code alone.
Encryption at rest
AES-256-GCM, with keys bound to the row they protect.
Learner identifiers
The identifier the learning management system supplies is an xAPI account of home page and name. Email-style identifiers are refused. It is stored only as a keyed token.
Client addresses
Never stored. Request logs carry a keyed token in place of an IP address.
Stored objects
Course packages and erasure records are encrypted on our host before they are uploaded to object storage.

Data protection

Role
A processor, acting for the learning management system customer as controller. Article 28 terms are on the Data Processing Agreement page.
What is processed
The learner identifier the customer’s system supplies, and the learning records a course sends, including results and scores.
Retention
Per tenant and contractual. The defaults are 1,095 days for registrations and statement bodies, configurable down to one day.
Erasure
A learner’s records are pseudonymised in cmi5 immediately, their document copies in the LRS are stopped and removed, and the erasure is handed to the RODMENA LRS with a recorded receipt, so one request reaches both systems. After a database restore, every erasure is re-applied from sealed records kept outside the database, as a step of the restore procedure.
Operator reasons
The reason recorded for an erasure or a deletion is a ticket reference or a code, never free text about a person, because those records outlive the data.
Location
The same database tier the Trust Centre states, in the United Kingdom, France and Germany, with no other transfer.

Integrations

Document copies to the LRS
Optional and off by default, per customer. Saved-state and learner-preference documents are copied one way to the RODMENA LRS and deleted there when they are deleted or reach retention. Session launch data is copied without its entitlement key.
LRS cross-check
On request, a registration’s statements are compared with the LRS copy, and a signed result for each statement is added to the evidence pack.
Signed statements
Optional, per customer. The statements cmi5 writes itself (launched, abandoned, satisfied, waived) carry an xAPI digital signature with RODMENA’s service certificate. The signature is removed with the statement body at retention or erasure.
Webhooks
Optional. Event notifications go to HTTPS endpoints the customer registers, signed with HMAC-SHA256. They carry only ids the customer already holds and timestamps, never a learner identifier or a learning record. Events are kept for 30 days.

Exit and portability

Return of data
A customer requests an export through the API. It runs only after a second person approves it, is encrypted to the customer’s own key, and comes with a signed manifest covering every table the customer owns.
Deletion at contract end
Every record and every stored object version is removed. The customer receives a signed, timestamped deletion certificate listing what was deleted, what is kept and why, and what it does not cover.

Evidence

Completion evidence
Exported as a signed, timestamped pack that a third party can verify offline, without access to our systems.
Timestamping
A public RFC 3161 timestamp authority anchors the audit chain. It receives a SHA-256 digest of a signed chain head, about every fifteen minutes, and only for a customer whose chain has changed. No personal data, no identifiers and no statements are sent to it.
If the authority is unreachable
Learning, launches, statements and evidence export are unaffected. Anchoring retries on the next pass, the newest audit rows are simply not yet covered by an anchor, and each tenant’s health reports how long they have waited.

Accessibility

Partially conformant with WCAG 2.2 AA. Our surfaces meet WCAG 2.2 AA so that a public-sector customer can meet its duty under the Public Sector Bodies (Websites and Mobile Applications) Accessibility Regulations 2018. The Equality Act 2010 binds RODMENA directly.

This product

What this covers
The four pages a learner sees: the launch page; the app launch page (“Open your course in its app”), shown instead when a course opens in a separate app on the learner’s device, which never opens anything by itself and always waits for Continue; the page shown when a link has expired or has already been used; and the error page. Course content itself belongs to the customer and is outside this statement.
Automated testing
axe-core 4, WCAG 2.2 AA plus its best-practice rules: 20 checks clean out of 20, covering five page forms (launch, app launch, expired with and without a way back, error) at desktop and phone widths in both the light and the dark theme, run against the live pages on 26 September 2026.
Screen reader
Tested with Orca 46 and Google Chrome on Linux on every page. Each page is announced with its title or main landmark, and the single control as “Continue push button” or “Return to the course page link”.
Keyboard
Tested by keyboard alone in Google Chrome on macOS and Linux. The first Tab reaches the only control on each page, with a visible 3 px focus state. On macOS, Chrome and Safari skip links on Tab unless “Press Tab to highlight each item” is on; Option+Tab reaches them either way.
Without JavaScript
The launch page submits on its own where scripting is available, and a visible Continue button is the path where it is not. Nothing on these pages requires a script.
No time limits
No countdown and no time limit is presented to the learner on any of the pages.
Built from
Plain semantic HTML with one main landmark, a single-column layout and a polite live region for status. No third-party user-interface framework is used.
Not yet done
Testing with VoiceOver, NVDA or JAWS, and TalkBack, and a third-party accessibility audit. Until the audit is complete the statement stays at partially conformant, and we will say so to any buyer who asks.
Reporting a problem
Accessibility problems with these pages go to the address on our accessibility statement, and we answer them there.

What it does

  • Conformance-tested

    Passes the ADL CATAPULT cmi5 LMS test suite: 21 of 21 package tests and 66 of 66 runtime tests.

  • Rules enforced at the door

    Every statement a course sends is checked against the cmi5 session and verb rules, and a refusal names the requirement it breaks.

  • Keeps working through an outage

    Records are accepted and held, then forwarded exactly once and in order. A ten-minute LRS outage with 200 learners caused no learner-facing errors.

  • Isolated and encrypted

    Each customer’s data is separated by database row-level security, encrypted at rest, and learner identifiers are stored only as keyed tokens.

  • Evidence a third party can check

    Completion evidence is exported as a signed, timestamped pack that verifies offline without access to our systems.

  • Erasure that reaches the LRS

    A learner’s erasure is applied immediately in cmi5 and handed to the LRS with a recorded receipt.

For documentation, a pilot or an integration, contact us.