Security, privacy & compliance

Everything a buyer or security reviewer needs to assess RODMENA as a supplier — with live, honest statuses for every claim.

How to read this page. RODMENA is a young company (incorporated May 2025) building its assurance portfolio in the open. Every certification below shows its real status — certified, in progress or planned — and this page updates the day anything changes. We would rather show you an honest roadmap than an inflated claim.

Security overview

RODMENA is a UK software company built around durable, fault-tolerant engineering. We apply the same discipline to our own security: encryption in transit for all services, least-privilege access to systems, hardened self-managed infrastructure, and a development practice designed so that failures are contained and recoverable. We hold minimal personal data — business correspondence only — and we do not use analytics, trackers or advertising cookies on this website.

The full detail — access control, encryption, secure development, backups, vulnerability management and incident response — is in our security whitepaper.

Security contact: enquiries@rodmena.co.uk (see also responsible disclosure and security.txt).

Certifications & compliance

Certifications and their current status
CertificationStatusIssuedExpiresEvidence
Cyber EssentialsIASME (UK NCSC scheme)Preparing against the 2026 question setPlanned
Cyber Essentials PlusIASME (UK NCSC scheme)Planned to follow Cyber EssentialsPlanned
ICO Data Protection RegistrationInformation Commissioner's OfficeRegistration reference ZC202334 (Tier 1) — verify on the public ICO registerRegistered19 July 202618 July 2027View · Certificate (PDF)
ISO/IEC 27001 (Information Security)UKAS-accredited certification bodyOn the roadmap as the company growsPlanned

Penetration testing: Planned — a summary of scope and findings will be published here after the first engagement.

Insurance

Insurance policies and their current status
CoverStatusDetails
Professional IndemnityPlannedInsurer and limits will be published once bound
Public LiabilityPlannedInsurer and limits will be published once bound
CyberPlannedInsurer and limits will be published once bound

Privacy & data protection

We hold minimal personal data — business correspondence only — and this website sets no cookies and runs no analytics or trackers. Our Privacy Policy describes processing in detail, and our Data Processing Agreement page explains the Article 28 terms we offer. DPA requests: enquiries@rodmena.co.uk.

Sub-processors

Sub-processors and their purpose and location
ProviderPurposeLocation
Dedicated bare-metal servers (provider selected per engagement)Website & application hosting, self-managed by RODMENAConfirmed per engagement — details available on request
GitHub, Inc.Source code hosting & CIUSA (Standard Contractual Clauses)

Responsible disclosure

If you believe you have found a security vulnerability in this website or in any RODMENA product, please email enquiries@rodmena.co.uk with enough detail for us to reproduce the issue. We will acknowledge your report, normally within three working days, keep you informed of progress, and credit you if you wish once the issue is resolved.

We will not take legal action against good-faith security research that respects user privacy, avoids service disruption and gives us reasonable time to fix issues before public disclosure. Our machine-readable policy lives at /.well-known/security.txt.

Service & support

Support is provided directly by the engineers who build our systems. Severity definitions, response expectations and maintenance windows are described on the Service & SLA page; specific uptime and response targets are agreed per contract so that every commitment we make is one we can keep.

Severity definitions and the support model are on the Service & SLA page; exit & portability explains how customers leave cleanly. A public status page is planned and will be linked here.

More