Isolated by workspace
Profiles, glossaries, uploaded files, runs and reports belong to a single workspace. There is no shared pool of customer content, and one tenant cannot read another. Red-teamed for cross-tenant leakage.
Unreleased campaigns, pricing and product names pass through this system. Rather than claim certifications we do not hold, here is exactly how your content is handled at each layer, and where the limits are.
The deterministic rules run without a model. The AI review, the second opinion and the spelling report send the segments they need to the provider your workspace allows, as fenced text, and the findings come back into your workspace. The profiles we ship have it on; a profile can switch it off.
Used to train shared models. Sold. Pooled with another customer's content. Returned to you as another tenant's data.
Profiles, glossaries, uploaded files, runs and reports belong to a single workspace. There is no shared pool of customer content, and one tenant cannot read another. Red-teamed for cross-tenant leakage.
We process your bilingual files to run the check and produce a report, and no more. The uploaded file is removed within 24 hours; the report stays in your workspace until you ask us to delete them.
Sign-in is per workspace and roles decide what each member can reach. Translators see only their own runs.
Hiding a page is a courtesy. Every permission is checked again server-side, so a hand-typed URL or a deep link returns a refusal rather than data.
An unmapped organisation, an unknown project or a bad signature is refused. A check that could not run reports as not checked, never as passed.
We read the bilingual file. Corrections are made by a person in your own tool, so nothing we do can corrupt a delivery.
Connecting a platform means trusting us with a token. Here is what happens to it, and how we stop someone else's traffic reaching your workspace.
Visibility is the role allow-list and the module gate together. A module your workspace has not bought is not there for anyone, whatever their role.
| Area | Admin | Quality lead | PM | Linguist | Translator |
|---|---|---|---|---|---|
| Run a check | yes | yes | yes | yes | yes |
| Reports | yes | yes | yes | yes | own runs |
| Profiles · view | yes | yes | yes | yes | no |
| Profiles · edit | yes | yes | yes | owner only | no |
| LQA and Eval | yes | yes | yes | yes | no |
| Analytics | yes | yes | yes | yes | no |
| Integrations | yes | yes | yes | no | no |
| Workspace settings | yes | yes | yes | no | no |
| Members and branding | yes | no | no | no | no |
| API keys and webhooks | operator | no | no | no | no |
Global engine configuration sits with the platform operator, not with a customer admin. Branding does not: a customer admin can white-label their own workspace.
The deterministic rules do their work with no model involved. When a model is used, these constraints apply.
Source and target text is wrapped as untrusted data before it reaches a model, with an instruction to judge it rather than obey it. Segments go in small batches, each fenced separately. A segment that contains instructions is content, not a command. A rule finding the second model disputes stays in the report and does not count toward the quality score.
Your segments are never used to train our models.
The profiles we ship have it on. Switching the AI review off in a profile does not switch off the second opinion or the spelling report; with all three off, no segment text leaves the platform. Your workspace admin chooses which providers may receive its text.
The model proposes and a second model gives its opinion. A reviewer confirms or overrides, and no verdict is final without one.
AI calls run on our own accounts with each provider, not on keys you supply. New workspaces allow Google Gemini, OpenAI and DeepInfra; DeepSeek stays off until an admin allows it.
Uploaded files are removed within 24 hours. Reports and scorecards stay in your workspace; ask us to delete them and we do.
We are a working product, not a certification. We are not claiming SOC 2 or ISO 27001, and we will not imply one is in progress to move a deal along. If a specific control matters to your procurement, ask and we will tell you exactly where we stand on it, including where the answer is no.
Background work is shared across tenants, so a very large job can slow other tenants' queued work. Large platform-wide scans are capped and labelled partial. Some content formats are out of scope.
If you think you have found a security issue, tell us privately first, give us a reasonable window to respond and please do not access data that is not yours while testing. Use the contact form and it reaches a person.
Procurement checklist, data handling or integration scopes: send it over
Tell us your stack and the question. If the honest answer is that we do not have that control yet, that is the answer you get.