Trust Centre
Security, privacy and compliance
Everything a buyer or security reviewer needs to assess RODMENA as a supplier, with a live, honest status for every claim.
Security overview
RODMENA is a UK software company built around durable, fault-tolerant engineering. We apply the same discipline to our own security: encryption in transit for all services, least-privilege access to systems, hardened self-managed infrastructure, and a development practice designed so that failures are contained and recoverable. We hold minimal personal data, business correspondence only, and this website uses no analytics, trackers or advertising cookies.
The full detail, access control, encryption, secure development, backups, vulnerability management and incident response, is in our security whitepaper.
Security contact: security@rodmena.co.uk (see also responsible disclosure and security.txt).
Certifications and compliance
| Certification | Status | Issued | Expires | Evidence |
|---|---|---|---|---|
| Cyber Essentials IASME (UK NCSC scheme). Preparing against the 2026 question set | Planned | — | — | — |
| Cyber Essentials Plus IASME (UK NCSC scheme). Planned to follow Cyber Essentials | Planned | — | — | — |
| ICO Data Protection Registration Information Commissioner's Office. Registration reference ZC202334 (Tier 1); verify on the public ICO register | Registered | 2026-07-19 | 2027-07-18 | Register entry Certificate (PDF) |
| ISO/IEC 27001 (Information Security) UKAS-accredited certification body. On the roadmap as the company grows | Planned | — | — | — |
Penetration testing: Planned A summary of scope and findings will be published here after the first engagement.
Insurance
| Cover | Status | Details |
|---|---|---|
| Professional indemnity | Planned | Insurer and limits will be published once bound |
| Public liability | Planned | Insurer and limits will be published once bound |
| Cyber | Planned | Insurer and limits will be published once bound |
Privacy and data protection
We hold minimal personal data, business correspondence only, and this website sets no cookies and runs no analytics or trackers. Our Privacy Policy describes processing in detail, and our Data Processing Agreement page explains the Article 28 terms we offer.
DPA requests: legal@rodmena.co.uk · privacy and data-protection questions: privacy@rodmena.co.uk · data-subject requests: gdpr@rodmena.co.uk.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| OVH SAS (OVHcloud) | Managed virtual servers hosting the production database tier and its encrypted off-site backups | United Kingdom, France and Germany |
| Self-managed virtual servers on company-owned hardware | Website and application hosting, administered by RODMENA | United Kingdom |
| GitHub, Inc. | Source code hosting and CI | USA (Standard Contractual Clauses) |
Responsible disclosure
If you believe you have found a security vulnerability in this website or in any RODMENA product, please email security@rodmena.co.uk with enough detail for us to reproduce the issue. We will acknowledge your report, normally within three working days, keep you informed of progress, and credit you if you wish once the issue is resolved.
We will not take legal action against good-faith security research that respects user privacy, avoids service disruption and gives us reasonable time to fix issues before public disclosure. Our machine-readable policy lives at /.well-known/security.txt.
Service and support
Support is provided directly by the engineers who build our systems. Severity definitions, response expectations and maintenance windows are described on the Service and SLA page; specific uptime and response targets are agreed per contract so that every commitment we make is one we can keep.
Severity definitions and the support model are on the Service & SLA page; exit & portability explains how customers leave cleanly. A public status page is planned and will be linked here.
Policies
- Information Security Policy Published
- Secure Software Development Policy Published
- Modern Slavery Statement Published
- Anti-Bribery & Fraud Policy Published
- Equality & Diversity Policy Published
- Environmental Policy Published
- Whistleblowing / Speak-Up Policy Published
- Conflicts of Interest Policy Published
More
- Company information: Companies House details, procurement identifiers, insurance
- Security whitepaper: access control, encryption, secure development, incident response
- Data processing: roles, sub-processors, transfers, retention, breach handling
- Service & SLA: support model, severity definitions, maintenance windows
- Exit & portability: standard export formats, migration support, deletion certificate
- Social value & carbon reduction: proportionate commitments and our Carbon Reduction Plan
- Accessibility statement: our WCAG 2.2 AA commitment and current status
- Privacy Policy: how we handle personal data (UK GDPR / DPA 2018)
- Terms of Service: standard website terms