AppCode Solutions
Security at AI Blog
We use layered controls and make specific, verifiable claims rather than promising perfect security.
Payments
Checkout is hosted by Stripe, so full card details do not pass through or get stored on AppCode servers. Stripe identifies itself as a PCI Level 1 service provider.
Email and personal data
Newsletter addresses are encrypted at application level with AES-256-GCM and unique nonces. Keyed lookup values avoid storing searchable plaintext addresses. Resend states that it is SOC 2 Type II and GDPR compliant and encrypts data at rest and in transit.
Infrastructure
Production services run in isolated containers behind HTTPS. Databases and private APIs have no public ports. Internal requests, provider webhooks and newsletter links are authenticated, and database backups are encrypted before off-site storage.
Responsible disclosure
Please report suspected vulnerabilities privately through the contact page. Do not access or modify data that is not yours.