01Accounts and access
- Organization membership and project access are checked on the server for every request.
- Roles separate viewers, editors, admins, and owners. Only editors and above can change translations; publishing is an explicit action.
- Passwords are hashed with a modern adaptive algorithm. Sessions use secure, HTTP-only cookies.
- Enterprise organizations can require SSO with SAML.
02Project tokens
- Tokens are scoped to one project and environment, stored only as hashes, and shown once when created.
- Tokens can be rotated or revoked at any time from the dashboard.
- The SDK keeps project tokens in build configuration and CI secrets. Browser code receives only a publishable key that cannot upload or change content.
03Data protection
- All traffic uses TLS 1.2 or later.
- Databases, file storage, and backups are encrypted at rest by our infrastructure providers.
- Translation requests include only the source text and context needed to produce a result. Your content is not used to train models.
- Application logs omit source copy, translations, authorization headers, and payment data.
04Safe releases
Nothing reaches your users until someone publishes it. Each release is a fixed, versioned catalog, and any earlier version can be restored immediately. Spend limits stop translation runs before they exceed the budget you set.
05Infrastructure
Linguana runs on established cloud providers with their own physical security and compliance programs. Production access is limited to the people who need it and is logged. Dependencies are monitored for known vulnerabilities.
The full list of providers is in the privacy policy.
06Report a vulnerability
If you believe you have found a security issue, email security@linguana.dev with steps to reproduce. We will acknowledge your report within 3 business days and keep you updated until it is resolved.
Please act in good faith: avoid accessing other customers' data, degrading the Service, or disclosing the issue publicly before we have fixed it. We will not pursue legal action against research that follows these guidelines.