Skip to content
/trustwritten for a security review

listed.

How we handle your data.

every category that can see your text is listed, names on request

What happens to your strings, who else can see them, how long we keep them, and where we stand on SOC 2 and GDPR. Including the answers that are still no.

  • we do not train on your content
  • tls 1.2 or better in transit
  • signed webhooks, hashed tokens
  • translation memory off per project
  • every subprocessor disclosed
compliance

Compliance, as it actually stands.

every row is read from the trust register when the page renders, so a certificate cannot appear here before the audit behind it does
Compliance,
We hold no third-party security certification today. Nothing on this page can draw one: the stamp comes from a boolean in config, and that boolean is false on every row.
where your data goes

Where your text goes, end to end.

Five stops, from your repository and back. The two lists underneath say what the shared translation memory keeps and what is stripped out of it first. All of it is in the DPA.

  1. ORIGIN

    your repository

    A file, a push, an API key. Nothing else leaves your side.
  2. TRANSPORT

    tls 1.2 or better

    Anything older is refused at the edge rather than quietly downgraded.
  3. STORAGE

    the database

    Every query is scoped to your organization and project. Backups are encrypted with AES-256 before they leave the host.
  4. COMPUTE

    the translation engine

    Your strings go to the providers on the subprocessor list to be translated, and for nothing else, under commercial terms. Metering records token counts, never the text.
  5. RETURN

    your branch

    Translations land back where the strings came from, each stamped with what produced it.
What the shared memory keeps
  • The source string and its translation (the linguistic pair only), keyed by a hash of the source.
  • Plural forms, where the string is pluralized.
  • Aggregate reuse counters (how often an entry was reused) for savings analytics.
What it never keeps
  • Any link to the person or the team behind an entry. There is no user column and no team column, so nothing in the pool can be traced back to who wrote it.
  • The workspace and project behind an exact-match entry: the pooled pair is written with no owner at all. A reviewed entry is the one exception, and there the workspace id is a fence rather than a label. Near-match (semantic) lookup filters on it, which is exactly what stops a reviewed entry from ever being returned to another workspace.
  • The translation key name, file path, screenshots, comments, and every other piece of surrounding context.
  • Request bodies: metering records token counts for billing, never the content of a request.
uptime

We do not print an uptime number here.

we publish no figure we measured ourselves, and a percentage typed into a page is out of date the moment it is written

There is no number in this band, and that is on purpose.

  • A percentage typed into a marketing page is out of date the moment it is written, and nobody edits it after an incident.
  • We monitor our own infrastructure, but a figure we measured ourselves is still our word for our own availability.
  • The status page below is run by an independent provider. It is the one we watch, and it answers whether or not this site is up.
  • Contractual uptime targets are promises rather than measurements, so they live on the SLA page with the service credits attached.
STATUS

The status page

Uptime and incident history are published by an independent provider, on infrastructure separate from the product it reports on.

externally hosted
THE SLA

Targets, in writing

Business and Enterprise carry a contractual monthly uptime target with a service-credit schedule. Free, Starter and Team are best effort, and the SLA page says so.

/sla
PROCESSORS

Who else touches your text

The full list, with the region each one runs in and when it is in the path at all. Adding a provider without listing it here fails our build.

5 listed
the trust register
ACCESSIBILITY

WCAG 2.1 AA, targeted

Keyboard navigation throughout, focus handling on dialogs and the command palette, screen-reader labels on the translation grid, a reduced-motion mode, and automated axe-core checks in CI.

a target, not a certificate
report a vulnerability

Found a security problem?

the address reaches an engineer rather than a ticket queue
who reads it
An engineer, not a triage bot. security@transglot.ai sits beside privacy@transglot.ai in the same register, and those two are the only addresses we publish.
safe harbour
Research done in good faith under the policy is authorised, and we will not pursue or support legal action over it. That is written into the policy, not offered case by case.
how fast we reply
Three business days to acknowledge, ten business days to give you an initial assessment and a severity, and normally ninety days to ship a fix for anything high or critical. If it will take longer we tell you why.
what we ask of you
Use only accounts you own, take nothing that is not yours, and give us ninety days before publishing. There is no paid bounty today.
the whole policy
Thirteen clauses at /legal/vulnerability-disclosure: what is in scope, what is out, and the four things we promise never to do.
disclosure, illustrative
~ % mail security@transglot.ai
Contact: security@transglot.ai
Also: privacy@transglot.ai
Published at: /.well-known/security.txt
Scope: the app, the API and this site
Safe harbour: in writing, clause 07
We acknowledge: within 3 business days
We assess: within 10 business days
Please hold: 90 days before publishing
Paid bounty: none today

FAQs

What a security review asks, in the words people actually use.

Do you train AI models on my content?
No, on any plan. Your strings go to the providers on the subprocessor list to be translated and for nothing else, under commercial terms. Metering records token counts for billing, never the text of a request.
Not yet. A SOC 2 Type II audit is in progress: Type I readiness first, then the Type II observation window, and we will publish the report here when it is done. We hold no third-party security certification today, and the compliance table above is rendered from a config value that cannot show a certificate we do not hold.
We process personal data in line with the GDPR, we sign a Data Processing Addendum, and we handle EU data subject access and deletion requests. GDPR is a regulation rather than a certificate, so nobody can hold a GDPR certification, and we do not claim one.
In one cloud region, fixed at deployment, on AWS. There is no per-project region pinning today and we do not sell one. If data residency is a hard requirement for you, tell us before you start rather than after.
The subprocessors listed in the trust center, each with the region it runs in and the condition that puts it in the path. The list is enforced rather than maintained by hand: routing a new provider without disclosing it fails our build.
Yes. The Data Processing Addendum is a page you can read right now, before anyone signs anything. Mail privacy@transglot.ai for an executed copy for your files.
The exact-match memory pool is shared and carries no owner: no person, no team, no workspace. Any project can leave it with one switch, on every plan. Near-match memory is scoped to your organization, needs a Team plan or higher, and stays off until a project turns it on.
Screenshots and assistant conversations 90 days, the activity feed 180 days, audit events until the organization is purged. Deleting an organization cascades it out of the live database 30 days later. Encrypted backups are not reached by that purge and roll off on their own schedule.
Uptime is reported by an independent status provider rather than by us. Business and Enterprise carry a contractual monthly uptime target with a service-credit schedule, set out on the SLA page. Free, Starter and Team are best effort.
Mail security@transglot.ai. The published policy gives you a written safe harbour, an acknowledgement within three business days and an initial assessment within ten business days. There is no paid bounty today.
Yes, on Enterprise: SAML 2.0 sign-in with just-in-time provisioning, SCIM 2.0 user provisioning, and the option to switch password login off for the whole organization. Four roles and per-language grants are on every plan, Free included.
The trust center answers most of one already, in writing, including the answers that are no. If yours asks something it does not cover, mail security@transglot.ai and an engineer replies. If the answer belongs on the page, it goes on the page.
still blocked? mail security@transglot.ai and an engineer replies
works with what you already run

41 connectors, already built.

before you sign anything

Check us before you trust us.

DPA at /legal/dpa · subprocessors at /legal/subprocessors · no certificate claimed