004Security and data

Practices,
not badges.

Unreleased campaigns, pricing and product names pass through this system. Rather than claim certifications we do not hold, here is exactly how your content is handled at each layer, and where the limits are.

One workspace per customer Your content never trains our models DPA on Business and Enterprise
Model
Multi-tenant SaaS
Isolation
Per workspace
Roles
5 + operator
Certifications
None claimed
What leaves your workspace

The deterministic rules run without a model. The AI review, the second opinion and the spelling report send the segments they need to the provider your workspace allows, as fenced text, and the findings come back into your workspace. The profiles we ship have it on; a profile can switch it off.

Never

Used to train shared models. Sold. Pooled with another customer's content. Returned to you as another tenant's data.

EKAsk for the detail and you get the limits tooreviewed 2026
01Posture

What we protect,
and how

01

Isolated by workspace

Profiles, glossaries, uploaded files, runs and reports belong to a single workspace. There is no shared pool of customer content, and one tenant cannot read another. Red-teamed for cross-tenant leakage.

02

Least data by default

We process your bilingual files to run the check and produce a report, and no more. The uploaded file is removed within 24 hours; the report stays in your workspace until you ask us to delete them.

03

Access is scoped

Sign-in is per workspace and roles decide what each member can reach. Translators see only their own runs.

04

Enforced in the API

Hiding a page is a courtesy. Every permission is checked again server-side, so a hand-typed URL or a deep link returns a refusal rather than data.

05

Fails closed

An unmapped organisation, an unknown project or a bad signature is refused. A check that could not run reports as not checked, never as passed.

06

Your file is not edited

We read the bilingual file. Corrections are made by a person in your own tool, so nothing we do can corrupt a delivery.

02Connectors

Credentials you hand over
are treated like credentials

Connecting a platform means trusting us with a token. Here is what happens to it, and how we stop someone else's traffic reaching your workspace.

At restEncryptedConnector secrets are encrypted in storage and are never returned by the API, including to you.
WebhooksSigned and freshVerified with your workspace's own secret, inside a five-minute window, with per-tenant replay protection.
RoutingOne owner per projectA platform project belongs to exactly one workspace. A conflict routes to neither until an operator resolves it.
RefusalsIdentical answersThe webhook answers every rejection the same way, so it cannot be used to discover which projects are connected.
InstallOwnership verifiedA platform install is checked server-side against the organisation that claims it.
ScopeRead what is publishedWe fetch the bilingual file for the locale in the event. Nothing in your platform is modified.
DiagnosticsVisible skipsA delivery we chose not to run is recorded with the reason, rather than silently dropped.
EntitlementChecked on every pathA suspended or view-only workspace is refused on the webhook exactly as it is in the interface.
03Roles

Five roles,
three modules

Visibility is the role allow-list and the module gate together. A module your workspace has not bought is not there for anyone, whatever their role.

AreaAdminQuality leadPMLinguistTranslator
Run a checkyesyesyesyesyes
Reportsyesyesyesyesown runs
Profiles · viewyesyesyesyesno
Profiles · edityesyesyesowner onlyno
LQA and Evalyesyesyesyesno
Analyticsyesyesyesyesno
Integrationsyesyesyesnono
Workspace settingsyesyesyesnono
Members and brandingyesnononono
API keys and webhooksoperatornononono

Global engine configuration sits with the platform operator, not with a customer admin. Branding does not: a customer admin can white-label their own workspace.

04AI providers

The model layers are
fenced and yours to switch

The deterministic rules do their work with no model involved. When a model is used, these constraints apply.

01

Document text is fenced

Source and target text is wrapped as untrusted data before it reaches a model, with an instruction to judge it rather than obey it. Segments go in small batches, each fenced separately. A segment that contains instructions is content, not a command. A rule finding the second model disputes stays in the report and does not count toward the quality score.

02

Not training data

Your segments are never used to train our models.

03

A setting you control

The profiles we ship have it on. Switching the AI review off in a profile does not switch off the second opinion or the spelling report; with all three off, no segment text leaves the platform. Your workspace admin chooses which providers may receive its text.

04

A person still signs

The model proposes and a second model gives its opinion. A reviewer confirms or overrides, and no verdict is final without one.

05

Platform keys, your allow-list

AI calls run on our own accounts with each provider, not on keys you supply. New workspaces allow Google Gemini, OpenAI and DeepInfra; DeepSeek stays off until an admin allows it.

06

Retention you can see

Uploaded files are removed within 24 hours. Reports and scorecards stay in your workspace; ask us to delete them and we do.

05What we do not claim

No badges
we cannot show you

We are a working product, not a certification. We are not claiming SOC 2 or ISO 27001, and we will not imply one is in progress to move a deal along. If a specific control matters to your procurement, ask and we will tell you exactly where we stand on it, including where the answer is no.

A

Known limits

Background work is shared across tenants, so a very large job can slow other tenants' queued work. Large platform-wide scans are capped and labelled partial. Some content formats are out of scope.

B

Responsible disclosure

If you think you have found a security issue, tell us privately first, give us a reasonable window to respond and please do not access data that is not yours while testing. Use the contact form and it reaches a person.

Procurement checklist, data handling or integration scopes: send it over

006Procurement

Send the checklist,
we answer plainly

Tell us your stack and the question. If the honest answer is that we do not have that control yet, that is the answer you get.