To be very clear: Beta, production, rollout and staging environments are secure. They run all the same front end security provisions, same data center, same patches, etc. The difference is they run differing versions of the code base based on development.
In production environments, they do not.
This is exactly why data masking technologies exist. To mask/transform production data in non-production to that non-production has meaningful data but not REAL data
The only real additional risk here is running non-production code against live data; e.g. the risk of a feature branch sending extra email to customers. Given the nature of their products this is probably manageable, assuming they don't run batch jobs (via eg. resque)
Thanks for the reference to data masking; it should be more common.
My other thought on this was if they use any separate static web asset management or it's all one single environment-switching for ruby.
These days one could easily work with the stable REST server and all the web assets are switched between staging/beta/etc envs.
See my response to gyepi below for more info