Security
DevCard is in pre-launch closed beta. The controls below describe what is in place today. Where we are not yet certified, we say so.
Last updated: 2026-05-07.
SOC 2 Type II audit is scoped for the v50.0 General Availability milestone. Pre-launch operates under best-practice controls described below — the gap is auditor attestation, not the controls themselves. Procurement teams who require SOC 2 today should treat DevCard as not-yet-eligible and revisit at GA.
Report security issues to security@devcard.com. Pre-launch SLA targets:
We act in good faith with researchers who follow responsible disclosure: do not exfiltrate data beyond what is needed to demonstrate the issue, do not degrade service for other users, and give us reasonable time to remediate before publishing.
Pre-launch posture excludes the following — each is scoped for v50.0 GA or later:
See also: Privacy · Terms · Methodology