<!-- LLM_VERSION_INFO
FORMAT: text/markdown
CONTENT_TYPE: article
ORIGINAL_URL: https://www.devcycle.com/security
ALTERNATE_VERSION: security/index.html (text/html)
EXTRACTION_DATE: 2026-04-18T22:16:36.392Z

This is the markdown version with text-only content (images converted to alt-text).
For rich formatting with images, request the HTML version at: security/index.html
-->

🚀 DevCycle is Now Part of Dynatrace! [Learn more](https://blog.devcycle.com/devcycle-is-now-part-of-dynatrace/)

## Secure and Private by Design

# DevCycle Security and Compliance

DevCycle is committed to providing our users with a secure and compliant platform. To view our compliance reports please visit our Trust Center

[Access our Trust Center](https://trust.devcycle.com/) [View our Security Policy](https://github.com/DevCycleHQ/.github/blob/main/.github/SECURITY.md)

**SOC 2 Type II**\
\
Our SOC 2 Type II Compliance gives users the confidence that DevCycle has implemented robust controls to safeguard user data, maintain service availability, and ensure the reliability of your features.](https://trust.devcycle.com/) **CVE Numbering Authority**\
\
We are a registered CVE Numbering Authority and are committed to the responsible disclosure of any vulnerabilities that may impact our customers through issuing CVEs for our products and SDKs.](https://www.cve.org/PartnerInformation/ListofPartners/partner/DevCycle) **Vulnerability Disclosure Program**\
\
We currently operate a vulnerability disclosure program through HackerOne and do not currently have a bug bounty program, but we welcome responsible disclosure. For more information - see our security policy linked above.](https://hackerone.com/0f14ce17-36c7-4585-be89-b33f8b2d0f9c/embedded_submissions/new) **Data Privacy and Residency**\
\
We are fully GDPR compliant for a global adoption of DevCycle. If you have specific data residency requirements; contact us at support@devcycle.com and we can work with you on ensuring that your requirements are met.](https://www.dynatrace.com/company/trust-center/privacy/)

## Security & Compliance FAQs

Common questions about DevCycle's security, data privacy, and compliance practices.

- What customer data does DevCycle collect and store?+
- Where is customer data hosted (region and cloud provider)? What are the data storage locations?+
- Can data residency be controlled (e.g., EU-only storage)?+
- How long is audit log data retained?+
- How can I securely use PII in targeting rules?+
- Where can we find DevCycle's Security and Compliance documentation?+
