Security
Last updated 5 September 2026. Issued by RODMENA LIMITED.
Identity
Sign-in is delegated to RODMENA ID (OpenID Connect with PKCE). Sessions are held server-side, expire after twelve hours of inactivity or seven days in total, and end everywhere when you sign out at RODMENA ID.
Isolation
Every workspace's records are isolated at the database level by row-level security, and every document and file is encrypted at rest under a key held per workspace. Restricted documents are excluded from search indexing and from sharing.
Accountability
Every consequential action — sign-in, permission change, publication, download, share, deletion, administrative action — is recorded in an append-only, hash-chained audit trail that is anchored daily outside the service.
Reporting a concern
If you believe you have found a security issue, write to support@rodmena.co.uk with the details. Please do not test against other customers' workspaces.