Skip to content
Trust center

Everything a security review
asks for, already written.

Everything a security reviewer needs before the first call: who processes your text, what we keep and for how long, what the shared memory pool holds, and exactly where we stand on compliance, gaps included.

source: the trust register
no certificate claimed
Subprocessors

Who else can see your text.

listed by category and region rather than by vendor. we notify customers of material changes before a new subprocessor goes live, and some rows are conditional: the engaged note on each one says what has to happen before anything of yours is processed under it
  • AI

    AI inference

    The automated quality checks, glossary and vision features, and translation for languages the main engine cannot serve.

    United States
    Always, for AI features.
  • AI

    AI inference, translation engine

    Translation: an API router, and the model host behind it.

    United States and Singapore
    Always, for translation.
  • TE

    Text embeddings

    Embeddings for semantic (fuzzy) Translation Memory.

    United States
    Only when a project enables semantic Translation Memory (off by default).
  • CH

    Cloud hosting, database and object storage

    Runs the platform, the PostgreSQL database, and file storage.

    Configurable region
    Always (core infrastructure).
  • P

    Payments

    Billing and payment processing.

    United States / EU
    Only for customers on a paid plan.
The named vendor list, with each one’s own terms, is yours on request under NDA: write to privacy@transglot.ai. A category appears here the moment a vendor inside it becomes reachable, and adding one to the engine seam without a disclosure row fails the build.
The retention ledger

What we keep, and for how long

01
the trust register

Training on your content

Never, on any plan. Our AI subprocessors are called for inference only, under commercial terms.

02
the trust register

What metering stores

Token counts for billing, never the body of a request.

03
the project memory switch

Exact-match translation memory

A shared pool that names no person and no team, switchable off per project on every plan.

04
the semantic memory settings

Semantic (fuzzy) memory

Organization- and locale-scoped, and off until a project turns it on.

05
incontext:prune-screenshots

In-context screenshots

Kept 90 days, then pruned nightly.

06
assistant:prune

Assistant conversations

Kept 90 days, pruned nightly, and deleted with the account that made them.

07
activity:prune

Activity feed

Kept 180 days, then pruned nightly.

08
audit_events

Audit events

Append-only, and kept until the organization itself is purged.

09
organizations:purge

An organization you delete

Cascaded out of the live database 30 days after deletion, with billing cancelled first.

10
backup-storage.sh

The same organization in backups

Not reached by the purge. The encrypted snapshots roll off on their own windows, up to twelve monthly for files.

11
identity:prune

Federated login records

Kept only as long as the replay window they exist to protect.

12
the trust register

Where all of it runs

One cloud region, fixed at deployment. There is no per-project region pinning today and we do not sell one.

deletion and backup expiry are two clocks
every window is a config key, not a promise made on a call
Translation memory

The exact-match pool is shared, with a per-project switch.

the exact-match pool is global and anonymous by design. that is a trade, and the switch below is how you decline it
IN THE POOL

What a pooled entry holds

  • +The source string and its translation (the linguistic pair only), keyed by a hash of the source.
  • +Plural forms, where the string is pluralized.
  • +Aggregate reuse counters (how often an entry was reused) for savings analytics.
NOT IN THE POOL

What is stripped first

  • -Any link to the person or the team behind an entry. There is no user column and no team column, so nothing in the pool can be traced back to who wrote it.
  • -The workspace and project behind an exact-match entry: the pooled pair is written with no owner at all. A reviewed entry is the one exception, and there the workspace id is a fence rather than a label. Near-match (semantic) lookup filters on it, which is exactly what stops a reviewed entry from ever being returned to another workspace.
  • -The translation key name, file path, screenshots, comments, and every other piece of surrounding context.
  • -Request bodies: metering records token counts for billing, never the content of a request.
ONE SWITCH

The kill switch

Turning off "Translation memory" on a project stops it from both contributing to and drawing on the shared memory. The kill-switch is per project and available on every plan.

The source string and its translation can be reused across workspaces (that reuse is the point of a shared memory), but no entry names a person or a team, and the pool is never exposed as a browsable corpus.

A reviewed entry is the one that carries a workspace id, and it carries one so that it can be fenced in: near-match lookup filters on that id, so what your reviewers approve is only ever offered back to you. Exact-match reuse, the genuinely shared part, carries no owner at all.

Compliance

Where we stand, roadmap and all.

the same four rows /trust and /security read, from the same config, so no two of them can disagree
Where we stand,
We hold no third-party security certification today. Nothing on this page can draw one: the stamp comes from a boolean in config, and that boolean is false on every row.
The DPA

Read the DPA now, without asking for it.

Processor terms you can open in a tab before anyone signs anything. An executed copy comes by email when your legal team needs one on file.

Open the DPA
privacy@transglot.ai
WHAT IT COVERS
  • Controller and processor roles
  • The subprocessor list on this page, by reference
  • Breach notification without undue delay
HOW TO GET IT
  • Read it now at /legal/dpa
  • Ask for an executed copy by email
  • No procurement thread needed to read it
WHO ANSWERS
  • privacy@transglot.ai for the DPA and data subject requests
  • security@transglot.ai for a security review

FAQs

The answers a reviewer usually waits two weeks for. Where the honest answer is no, no is the first word.

Do you train AI models on our content?
No, on any plan. The subprocessors above receive your strings to translate them and for nothing else, under commercial terms, and metering records token counts rather than the text of a request.
The exact-match pool is shared and anonymous: it records no person, no team and no workspace, and any project can leave it with one switch. Near-match memory is scoped to your organization and locale, and a reviewed entry carries a workspace id as a fence, which is exactly what stops it from being returned to anybody else.
Screenshots and assistant conversations 90 days, the activity feed 180 days, audit events until the organization is purged 30 days after you delete it. The purge clears the live database, not the encrypted backups behind it, and those roll off on their own schedule. The ledger above lists every window beside the setting that controls it.
One cloud region, fixed at deployment, on AWS. Per-project region pinning does not exist today and is on the roadmap. If your contract needs a named region, raise it before you sign.
Not yet. Type I readiness first, then the Type II observation window. Nothing on this page can claim a certificate we do not hold: the compliance stamp is drawn from a boolean in config, and it is false on every row.
Yes to both. We process personal data in line with the GDPR and the Data Processing Addendum is a page you can read now, with an executed copy by email from privacy@transglot.ai. GDPR is a regulation rather than a certificate, so nobody holds a GDPR certification and we do not claim one.
SAML 2.0 sign-in with just-in-time provisioning and SCIM 2.0 provisioning ship on Enterprise, along with CSV export of the audit trail. Password login can be switched off for the whole organization. Four roles and per-language grants are on every plan, Free included.
security@transglot.ai reaches an engineer rather than a ticket queue. The published policy gives you a written safe harbour, an acknowledgement within three business days and an initial assessment within ten business days. There is no paid bounty today.
Deleting an organization cancels billing and cascades the data out of the live database 30 days later. Encrypted backups are on their own clock and are not reached by that purge. Your translations come out through the API pull endpoint, the CLI, the delivery bundle or file storage sync while the account is open.
still blocked? mail security@transglot.ai and an engineer replies. if the answer belongs on this page, it lands on this page.
works with what you already run

41 connectors, already built.

diligence, without the diligence call

Read it now. Ask us anything it does not answer.

security@transglot.ai · privacy@transglot.ai · dpa at /legal/dpa