🚀 DevCycle is Now Part of Dynatrace! Learn more
Secure and Private by Design
DevCycle Security and Compliance
DevCycle is committed to providing our users with a secure and compliant platform. To view our compliance reports please visit our Trust Center
Access our Trust Center View our Security Policy
SOC 2 Type II
Our SOC 2 Type II Compliance gives users the confidence that DevCycle has implemented robust controls to safeguard user data, maintain service availability, and ensure the reliability of your features.](https://trust.devcycle.com/) CVE Numbering Authority
We are a registered CVE Numbering Authority and are committed to the responsible disclosure of any vulnerabilities that may impact our customers through issuing CVEs for our products and SDKs.](https://www.cve.org/PartnerInformation/ListofPartners/partner/DevCycle) Vulnerability Disclosure Program
We currently operate a vulnerability disclosure program through HackerOne and do not currently have a bug bounty program, but we welcome responsible disclosure. For more information - see our security policy linked above.](https://hackerone.com/0f14ce17-36c7-4585-be89-b33f8b2d0f9c/embedded_submissions/new) Data Privacy and Residency
We are fully GDPR compliant for a global adoption of DevCycle. If you have specific data residency requirements; contact us at support@devcycle.com and we can work with you on ensuring that your requirements are met.](https://www.dynatrace.com/company/trust-center/privacy/)
Security & Compliance FAQs
Common questions about DevCycle's security, data privacy, and compliance practices.
- What customer data does DevCycle collect and store?+
- Where is customer data hosted (region and cloud provider)? What are the data storage locations?+
- Can data residency be controlled (e.g., EU-only storage)?+
- How long is audit log data retained?+
- How can I securely use PII in targeting rules?+
- Where can we find DevCycle's Security and Compliance documentation?+