Trust center
Security & trust
Factual architecture and controls for GlobalizationOS โ localization infrastructure for software and the web. This is not a certification page; external audits are listed only when obtained.
Tenant isolation
Organizations, workspaces, and integration projects are scoped by tenant identifiers enforced at the API layer. Cross-tenant reads and writes are rejected before business logic runs. Production API keys and browser credentials are bound to a single integration.
Authentication and credentials
Dashboard access uses passwordless email login codes. Access tokens are held in browser memory; refresh tokens use HttpOnly cookies with CSRF protection on mutations. API keys are hashed at rest; full secrets are shown once at creation. Role-based permissions gate billing, administration, and credential management.
Encryption and delivery
Customer-facing endpoints use HTTPS/TLS. Production secrets are injected from a secrets manager โ not committed to source. The localization runtime delivers pre-generated multilingual publications; visitor traffic does not trigger translation-provider generation on ordinary page loads.
Translate-Once integrity
PostgreSQL translation memory is authoritative. Unchanged canonical content reuses existing multilingual state. Intelligence routing applies only to genuinely new or changed meaning โ certified architecture, not marketing language.
Intelligence routing controls
Organizations can configure approved and prohibited provider keys, regulated routing tiers, and processing-region preferences where exposed. Regulated mode fails closed when no approved providers are configured.
Audit and monitoring
Privileged actions โ security policy changes, key rotation, domain updates, export requests โ emit structured audit records with actor identity and correlation IDs. Organization-scoped audit read APIs are available to authorized roles.
Current limitations (factual)
SAML/OIDC SSO login is not yet operational (configuration interfaces exist). MFA and SCIM are not implemented. GlobalizationOS does not currently hold SOC 2, ISO 27001, FedRAMP, or government accreditation. Data residency guarantees require contractual and infrastructure alignment beyond policy fields alone.
Security contact
Report vulnerabilities or begin a security review through your account team or support channel. We coordinate disclosure timelines with affected customers when remediation is required.