Security

Security at Playcode

What we do to keep your code, your data, and your customers safe. 10 years online, 99.9%+ lifetime uptime, no major security incidents.

SOC 2
In progress Β· consultant engaged
GDPR
In progress Β· EU primary hosting
EU Hosting
Bare-metal Β· Hetzner
Encryption
TLS in transit Β· at rest
99.9%+ Uptime
Lifetime, since 2016
DDoS Protection
Cloudflare edge

Compliance & certifications

SOC 2 Type IIIn Progress

We're actively pursuing SOC 2 Type II certification. Consultant engaged; gap analysis underway. Until certification completes, we can share our security overview, control mappings, and policy documents with procurement teams under NDA.

GDPRIn Progress

Your account, projects and databases are stored in the EU (Germany and Finland). AI requests go to the provider of the model you use, mostly in the US, and off-site backups are stored in the US; see the sub-processor list. Data subject rights (access, portability, erasure) are honored within 30 days; most within 24 hours. Downloadable DPA template available on request. On the roadmap: a cookie consent banner and explicit opt-in flows for analytics (Google Analytics + first-party event tracking). We're being honest about the gap so procurement teams know the exact compliance state when they evaluate.

Payment compliance

All payments processed by Stripe (PCI DSS Level 1). Playcode never stores or processes card data directly β€” every transaction is tokenized at Stripe's vault.

AI provider compliance

Our main AI providers (Anthropic, Google, OpenAI) carry SOC 2 Type II and offer GDPR data-processing agreements, and their paid API terms forbid training on the data we send. Models from xAI, DeepSeek, Moonshot, Z.ai and Alibaba run only when you select them, under those providers' terms and in the locations in our sub-processor list. We do not train models on your code or content.

Infrastructure & hosting

Bare-metal hosting

Dedicated physical servers in EU data centers (Hetzner). No shared-cloud noisy-neighbor risks, no surprise multi-tenancy, no hidden underlying infrastructure dependencies. Predictable performance, predictable security boundary.

Global edge protection

Cloudflare on every public request β€” DDoS mitigation, WAF rules, bot management, global CDN. Continuously online since 2016 with no major DDoS incidents that affected service.

AWS for elastic services

S3 for file storage and SES for email, in EU regions (Ireland and Frankfurt). CloudFront delivers static files from the global edge. Off-site backups are stored in the US (us-east-1). IAM-scoped, least-privilege roles per service.

HTTPS everywhere

TLS 1.2+ on every endpoint. Automatic certificate renewal via Let's Encrypt for customer domains. HSTS enabled, secure-cookie flags, modern cipher suites only.

Access control & operations

Minimal-surface production access

A single engineer holds production database access. By design β€” the smallest possible human attack surface. Every other operational task runs through audited, role-scoped tooling. Most enterprise breaches start with a compromised employee account; we have exactly one.

VPN-only server entry

Servers are not reachable from the public internet. SSH access requires WireGuard VPN authentication first, plus key-based SSH login (no passwords). All access events are logged.

No data sales

Your code and project content is never sold and never shared with advertisers. It goes only to the sub-processors in our Privacy Policy, to run the service. Our main AI providers do not train on it under their paid API terms.

Continuous monitoring

Prometheus + Grafana for infrastructure metrics, Sentry for application errors, custom uptime probes across regions. Production alerts page the engineering lead 24/7. 10 years of operational history.

Backups & recovery

Daily encrypted backups

Full database snapshots daily, retained for 30 days. WAL-G continuous archival for point-in-time recovery within the last 7 days. Backups encrypted at rest in separate storage from the primary database, with AWS in the US.

Disaster recovery

Documented runbooks for full database restore, infrastructure rebuild, and DNS failover. Recovery point objective (RPO) under 5 minutes; recovery time objective (RTO) under 4 hours for full restore from cold backup.

Data residency & deletion

Where your data lives

All primary data (projects, code, accounts, billing) is stored in EU data centers in Germany and Finland. Backups are stored with AWS in the US. AI requests go to the provider of the model you use. Every provider and its location is in our sub-processor list.

Right to be forgotten

Delete your account from the app at any time. All personal data is permanently removed within 30 days, with backup-rotation cleanup completing the erasure within 60 days. No retention beyond the legal minimum required for tax and financial records.

Code is yours

Every project on Playcode exports as real, runnable code (React, Vue, HTML, etc.). No vendor lock-in. You can leave with everything you built, anytime β€” and we'll permanently delete our copies when you do.

Project privacy

Paid plans default to private projects. Public projects (free tier) are clearly labeled. No silent data sharing between accounts.

Incident response

Suspected vulnerability? Confirmed incident? Email security@playcode.io with details. We acknowledge within 24 hours and triage immediately.

  • Disclosure: coordinated 90-day disclosure window for responsibly reported vulnerabilities.
  • Customer notification: impacted customers notified within 72 hours of confirmed breach (GDPR requirement).
  • Post-incident: public post-mortem after every Sev-1 incident.

No bug bounty program. Playcode does not pay for vulnerability reports and does not negotiate payment in exchange for a report, for silence, or for the deletion of data. A demand for payment is an extortion attempt, not a security report, and is referred to law enforcement.

We do not authorize security testing. Probing, scanning, and exploiting are not permitted, and neither is scraping or collecting other users' data. If you find something incidentally, without exploiting it and without touching anyone else's data, tell us privately and we will not come after you. Terms: Section 24 and Section 23.

For procurement teams

Need our security overview, DPA template, control mappings, or a custom questionnaire response? Email security@playcode.io and we'll respond within one business day.

DPA template
Standard EU GDPR data-processing agreement
Security overview
PDF covering all sections of this page
Sub-processor list
Questionnaire support
SIG, CAIQ, custom forms β€” 1-day SLA

Contact security

Vulnerability reports, security questions, procurement requests β€” one inbox, one-business-day response.