AppCode Solutions

Security at AI Blog

We use layered controls and make specific, verifiable claims rather than promising perfect security.

Payments

Checkout is hosted by Stripe, so full card details do not pass through or get stored on AppCode servers. Stripe identifies itself as a PCI Level 1 service provider.

Email and personal data

Newsletter addresses are encrypted at application level with AES-256-GCM and unique nonces. Keyed lookup values avoid storing searchable plaintext addresses. Resend states that it is SOC 2 Type II and GDPR compliant and encrypts data at rest and in transit.

Infrastructure

Production services run in isolated containers behind HTTPS. Databases and private APIs have no public ports. Internal requests, provider webhooks and newsletter links are authenticated, and database backups are encrypted before off-site storage.

Responsible disclosure

Please report suspected vulnerabilities privately through the contact page. Do not access or modify data that is not yours.