How we handle your data.
listed.
How we handle your data.
What happens to your strings, who else can see them, how long we keep them, and where we stand on SOC 2 and GDPR. Including the answers that are still no.
- we do not train on your content
- tls 1.2 or better in transit
- signed webhooks, hashed tokens
- translation memory off per project
- every subprocessor disclosed
Compliance, as it actually stands.
| Row | Framework | Where we are | What that means for your review | Ask us |
|---|---|---|---|---|
| 01 | SOC 2 Type II | audit in progress | Audit in progress. Type I readiness first, then the Type II observation window. We will publish the report here once complete. | |
| 02 | ISO/IEC 42001 (AI management) | pursuing | Pursuing early: the newest AI-governance standard. On the roadmap, not yet certified. | |
| 03 | GDPR | aligned, not certified | GDPR-aligned processing with a signable DPA, EU data-subject export and deletion on request. GDPR is a regulation we comply with, not a certificate. | |
| 04 | CCPA / CPRA | aligned, not certified | We honour California consumer access and deletion rights; we do not sell personal information. |
Where your text goes, end to end.
Five stops, from your repository and back. The two lists underneath say what the shared translation memory keeps and what is stripped out of it first. All of it is in the DPA.
- 01ORIGIN
your repository
A file, a push, an API key. Nothing else leaves your side. - 02TRANSPORT
tls 1.2 or better
Anything older is refused at the edge rather than quietly downgraded. - 03STORAGE
the database
Every query is scoped to your organization and project. Backups are encrypted with AES-256 before they leave the host. - 04COMPUTE
the translation engine
Your strings go to the providers on the subprocessor list to be translated, and for nothing else, under commercial terms. Metering records token counts, never the text. - 05RETURN
your branch
Translations land back where the strings came from, each stamped with what produced it.
- The source string and its translation (the linguistic pair only), keyed by a hash of the source.
- Plural forms, where the string is pluralized.
- Aggregate reuse counters (how often an entry was reused) for savings analytics.
- Any link to the person or the team behind an entry. There is no user column and no team column, so nothing in the pool can be traced back to who wrote it.
- The workspace and project behind an exact-match entry: the pooled pair is written with no owner at all. A reviewed entry is the one exception, and there the workspace id is a fence rather than a label. Near-match (semantic) lookup filters on it, which is exactly what stops a reviewed entry from ever being returned to another workspace.
- The translation key name, file path, screenshots, comments, and every other piece of surrounding context.
- Request bodies: metering records token counts for billing, never the content of a request.
We do not print an uptime number here.
There is no number in this band, and that is on purpose.
- A percentage typed into a marketing page is out of date the moment it is written, and nobody edits it after an incident.
- We monitor our own infrastructure, but a figure we measured ourselves is still our word for our own availability.
- The status page below is run by an independent provider. It is the one we watch, and it answers whether or not this site is up.
- Contractual uptime targets are promises rather than measurements, so they live on the SLA page with the service credits attached.
The status page
Uptime and incident history are published by an independent provider, on infrastructure separate from the product it reports on.
Targets, in writing
Business and Enterprise carry a contractual monthly uptime target with a service-credit schedule. Free, Starter and Team are best effort, and the SLA page says so.
Who else touches your text
The full list, with the region each one runs in and when it is in the path at all. Adding a provider without listing it here fails our build.
WCAG 2.1 AA, targeted
Keyboard navigation throughout, focus handling on dialogs and the command palette, screen-reader labels on the translation grid, a reduced-motion mode, and automated axe-core checks in CI.
Found a security problem?
- who reads it
- An engineer, not a triage bot. security@transglot.ai sits beside privacy@transglot.ai in the same register, and those two are the only addresses we publish.
- safe harbour
- Research done in good faith under the policy is authorised, and we will not pursue or support legal action over it. That is written into the policy, not offered case by case.
- how fast we reply
- Three business days to acknowledge, ten business days to give you an initial assessment and a severity, and normally ninety days to ship a fix for anything high or critical. If it will take longer we tell you why.
- what we ask of you
- Use only accounts you own, take nothing that is not yours, and give us ninety days before publishing. There is no paid bounty today.
- the whole policy
- Thirteen clauses at /legal/vulnerability-disclosure: what is in scope, what is out, and the four things we promise never to do.
FAQs
What a security review asks, in the words people actually use.