For more than two decades, Roblox has been on a mission to connect a billion people with optimism and civility. That mission runs on trust—trust that the platform is secure for the over 120 million daily active users who create, play, and build communities. Maintaining that trust requires a security program built for a challenge that has no real precedent in the industry.
Most enterprise security teams are protecting code their own engineers write, systems their own teams operate, and data their own business generates. At Roblox, that’s only part of the picture. Our platform is powered by millions of external creators, a live virtual economy, and an infrastructure that spans owned data centers, ephemeral cloud environments, and internal services. All of this is running simultaneously, and all requires consistent protection. The security challenges this creates are genuinely unlike anything else in tech. Below, I share how we think about those challenges, what we’ve built to address them, and where we’re headed next.
An Ecosystem Unlike Any Other
In addition to securing code produced by our own teams, Roblox’s business model involves running untrusted code written by millions of external creators. Every day, Roblox executes scripts from creators who may be new, inexperienced, and, occasionally, intent on bypassing our protections. That’s why our security model has to assume that any given piece of code could be malicious or exploitable. Sandboxing, isolation, and runtime monitoring aren’t nice-to-haves here; they’re the foundation that the entire platform runs on.
The infrastructure the platform sits on is equally complex. Securing Roblox means maintaining consistent threat visibility and policy enforcement across environments that couldn’t be more different: from owned data centers with fixed perimeters to ephemeral cloud instances that spin up and disappear in seconds. That requires automation and domain governance capable of operating at both speeds simultaneously. And unlike traditional enterprise security, where the primary assets are internal data and systems, Roblox’s attack surface includes a live economy: millions of virtual items selling for currency with real monetary value, user-generated IP that creators depend on for their livelihoods, and chat infrastructure serving tens of millions of people.
If a breach happens, it’s not just a data event, it’s direct harm to real people and real income. That reality shapes every decision we make. Our North Star is to make Roblox the most secure gaming platform at scale: a platform where creators and players can operate without ever having to think about cybersecurity. We measure progress by incidents prevented, as well as how quickly teams can ship securely, how widely our internal platforms are adopted, and the research we contribute to the broader community.
Security as an Enabler, Not a Gatekeeper
The compliance-driven model of enterprise security is over. Security teams that show up with requirements and leave partners to figure out implementation are bound to fall short. Not because engineers don’t care about security, but because it is inefficient to have thousands of engineers implementing bespoke security controls by hand. If the platform itself isn’t secured by default, security can’t scale.
Roblox inverts the compliance-driven model by building internal products that make the secure path the easy path, without removing developer responsibility. In practice, that means secret keys rotate automatically, so no engineer has to remember to refresh a credential. Working towards service-to-service communication authenticated by default, without engineers having to wire it up themselves, as our North Star. Security scorecards give every team a live view of their security posture. The secure choice is already available—the scorecard just shows whether it's being used and where more could be done.
Thoughtful AI Adoption in a Fast-Moving Landscape
As the industry debates how to handle AI tools—some companies greenlighting them without controls, others blocking them outright—Roblox is doing something different. We’re treating AI adoption as an engineering and security problem to be solved, and sharing what we learn with the broader community. Thoughtful adoption at Roblox means we test, we build controls, then we trust and monitor.
Before greenlighting AI code tooling internally, for example, we built a sandboxed environment. That kind of rigorous validation governs how every new AI tool gets approved for internal use. The goal isn’t to slow things down; it’s to make sure that as we move fast, we don’t create risks that are invisible until it’s too late. In this way, we’re building hands-on expertise in exactly the skills the industry is now scrambling to hire—demand for AI-related cybersecurity skills has grown 2.5x since 2020.
Our Commitment to Community
Information Security is fundamentally a collective defense problem. No company’s walls are high enough to hold off a motivated adversary alone, and the industry only gets stronger when practitioners share what they’ve learned. The threat landscape will keep evolving—AI is accelerating adversarial threats and threat actors—as will Roblox’s approach to meeting it. What won’t change is our commitment to the creators who entrust us with their work and livelihoods, the players who show up every day expecting a secure experience, and the broader security community we’re proud to be part of.
Security at this scale, with this much complexity, doesn’t have a finish line. But our philosophy is consistent: Build systems that make security the default, not the exception. Invest in the research and tooling that keep pace with an evolving threat landscape. And share what we learn so the whole industry gets stronger.











