generated: '2026-08-12' method: searched probe: true probe_result: >- probe-security-programs.py found no trust center at trust./security. subdomains or /trust|/security| /compliance paths (all 404). The compliance surface was located by SEARCH instead, at /iso-gdpr-security/ and /data-security/, and both artefacts are downloadable PDFs verified 200. url: https://playable.com/iso-gdpr-security/ pages: - {url: 'https://playable.com/iso-gdpr-security/', status: 200} - {url: 'https://playable.com/iso-270012013-gdpr/', status: 200} - {url: 'https://playable.com/data-security/', status: 200} - {url: 'https://playable.com/information-data-security-faqs/', status: 200} certifications: - name: ISO 27001:2022 scope: Information Security Management System evidence_url: 'https://content.playable.com/hubfs/E-guides/English/E-guides%20(PDF)/iso27001-2022-certificate-playable-2025.pdf' evidence_status: 200 year: 2025 - name: ISAE 3000 Type 2 scope: independent assurance assessment of GDPR compliance and data-protection controls evidence_url: 'https://content.playable.com/hubfs/E-guides/English/E-guides%20(PDF)/report-isae-3000-gdpr-fsr-type-2-playable-2025.pdf' evidence_status: 200 year: 2025 - name: GDPR scope: EU personal-data protection compliance statement evidence_url: https://playable.com/iso-gdpr-security/ evidence_status: 200 not_claimed: - SOC 2 - ISO 27017 - ISO 27018 - PCI DSS - HIPAA - FedRAMP - CSA STAR legal: dpa: https://playable.com/playable-dpa-v2/ privacy_policy: https://playable.com/privacy-policy-for-playable-aps/ terms: https://playable.com/terms-and-conditions-v2/ sub_processors: published: false vulnerability_disclosure: published: false note: >- No /.well-known/security.txt on playable.com or api.playable.com (both 404), no bug-bounty program on HackerOne/Bugcrowd/Intigriti, and no responsible-disclosure page or security@ address on any of the four compliance pages. help.playable.com serves a security.txt, but it is Intercom's vendor file, not Playable's. No VulnerabilityDisclosure artifact and no `Security` pointer is emitted — the surface genuinely is not published. x-evidence: - {fetched: '2026-08-12', url: 'https://playable.com/iso-gdpr-security/', http_status: 200, keywords: ['iso 27001:2022', 'isae 3000', 'gdpr']} - {fetched: '2026-08-12', url: 'https://playable.com/.well-known/security.txt', http_status: 404}