Security, privacy & compliance
Everything a buyer or security reviewer needs to assess RODMENA as a supplier — with live, honest statuses for every claim.
Security overview
RODMENA is a UK software company built around durable, fault-tolerant engineering. We apply the same discipline to our own security: encryption in transit for all services, least-privilege access to systems, hardened self-managed infrastructure, and a development practice designed so that failures are contained and recoverable. We hold minimal personal data — business correspondence only — and we do not use analytics, trackers or advertising cookies on this website.
The full detail — access control, encryption, secure development, backups, vulnerability management and incident response — is in our security whitepaper.
Security contact: enquiries@rodmena.co.uk (see also responsible disclosure and security.txt).
Certifications & compliance
| Certification | Status | Issued | Expires | Evidence |
|---|---|---|---|---|
| Cyber EssentialsIASME (UK NCSC scheme)Preparing against the 2026 question set | Planned | — | — | — |
| Cyber Essentials PlusIASME (UK NCSC scheme)Planned to follow Cyber Essentials | Planned | — | — | — |
| ICO Data Protection RegistrationInformation Commissioner's OfficeRegistration reference ZC202334 (Tier 1) — verify on the public ICO register | Registered | 19 July 2026 | 18 July 2027 | View · Certificate (PDF) |
| ISO/IEC 27001 (Information Security)UKAS-accredited certification bodyOn the roadmap as the company grows | Planned | — | — | — |
Penetration testing: Planned — a summary of scope and findings will be published here after the first engagement.
Insurance
| Cover | Status | Details |
|---|---|---|
| Professional Indemnity | Planned | Insurer and limits will be published once bound |
| Public Liability | Planned | Insurer and limits will be published once bound |
| Cyber | Planned | Insurer and limits will be published once bound |
Privacy & data protection
We hold minimal personal data — business correspondence only — and this website sets no cookies and runs no analytics or trackers. Our Privacy Policy describes processing in detail, and our Data Processing Agreement page explains the Article 28 terms we offer. DPA requests: enquiries@rodmena.co.uk.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Dedicated bare-metal servers (provider selected per engagement) | Website & application hosting, self-managed by RODMENA | Confirmed per engagement — details available on request |
| GitHub, Inc. | Source code hosting & CI | USA (Standard Contractual Clauses) |
Responsible disclosure
If you believe you have found a security vulnerability in this website or in any RODMENA product, please email enquiries@rodmena.co.uk with enough detail for us to reproduce the issue. We will acknowledge your report, normally within three working days, keep you informed of progress, and credit you if you wish once the issue is resolved.
We will not take legal action against good-faith security research that respects user privacy, avoids service disruption and gives us reasonable time to fix issues before public disclosure. Our machine-readable policy lives at /.well-known/security.txt.
Service & support
Support is provided directly by the engineers who build our systems. Severity definitions, response expectations and maintenance windows are described on the Service & SLA page; specific uptime and response targets are agreed per contract so that every commitment we make is one we can keep.
Severity definitions and the support model are on the Service & SLA page; exit & portability explains how customers leave cleanly. A public status page is planned and will be linked here.
Policies
- Information Security PolicyPublished
- Secure Software Development PolicyPublished
- Modern Slavery StatementPublished
- Anti-Bribery & Fraud PolicyPublished
- Equality & Diversity PolicyPublished
- Environmental PolicyPublished
- Whistleblowing / Speak-Up PolicyPublished
- Conflicts of Interest PolicyPublished
More
- Company informationCompanies House details, procurement identifiers, insurance
- Security whitepaperAccess control, encryption, secure development, incident response
- Data processingRoles, sub-processors, transfers, retention, breach handling
- Service & SLASupport model, severity definitions, maintenance windows
- Exit & portabilityStandard export formats, migration support, deletion certificate
- Social value & carbon reductionProportionate commitments and our Carbon Reduction Plan
- Accessibility statementOur WCAG 2.2 AA commitment and current status
- Privacy PolicyHow we handle personal data (UK GDPR / DPA 2018)
- Terms of ServiceStandard website terms