Security

Your data stays yours

SpectrHQ processes every document on infrastructure we operate and control, on SOC 2 Type II certified providers. No third-party AI service ever receives your content.

How we think about this

Most translation tools ask you to trust a policy

A privacy policy is a promise about what a company intends to do with your data. Promises can be revised, and they say nothing about the vendors sitting behind them, each operating under terms of their own.

SpectrHQ removes the question by removing the third party. We run our own translation models on infrastructure we operate and control. Your documents are processed there, and nowhere else. There is no outside AI service in the chain to trust, audit, or take on faith.

Data handling

How your content is held

Always encrypted

Your content is encrypted in transit and at rest, at every stage of the workflow.

Isolated per workspace

Files, terminology, and translation memory belong to your workspace. No other customer's workspace can reach them.

Restricted access

Access to customer content is limited to a minimal set of authorised SpectrHQ personnel, and only where operationally necessary.

Permanently deleted

When you delete a file, or when it reaches the end of your plan's retention period, it is permanently removed from storage. Not archived, not held in a recovery tier.

Retention runs 90 days on Light, one year on Base, and is unlimited on Enterprise. See plan details

Access control

Who can see what, and when

Every workspace runs on role-scoped permissions. People reach the work assigned to them and nothing beyond it.

Admins
Manage the workspace, assign files to reviewers, and confirm approved output.
Editors
Upload files and run translations.
Reviewers
Open assigned files, edit and approve translations, and cannot start new translation jobs or see jobs not assigned to them.
Enterprise

Activity records

Enterprise workspaces receive a compiled record of actions taken in the workspace, attributed to users

Commitments

Four things we never do

  1. Send your content to any third-party AI.

  2. Use your content to train shared models.

  3. Sell, share, or disclose your content outside your workspace.

  4. Retain your files beyond the retention period on your plan.

What we publish

Controls, not configurations

This page describes what we guarantee. We deliberately not name our infrastructure vendors or map our internal architecture, because that detail is more useful to an attacker than it is to a buyer. Under NDA, during security review, we go as deep as your team needs: architecture, processing locations, sub-processors, and your questionnaire in full.

Compliance

Where we stand

We would rather tell you exactly where our programme is than imply more than we have.

SOC 2
Under way. Type II expected in 2027.
Infrastructure
Operated on SOC 2 Type II certified providers.
Data processing agreement
Prepared for each Enterprise agreement on request.
Security questionnaires
Completed as part of procurement.

FAQ

The questions security teams ask

Is my content sent to any third-party AI service?

No. Translation runs on models SpectrHQ operates directly, on infrastructure we operate and control. Your documents are never submitted to an outside AI provider.

Do you train on customer data?

No. Your approved translations and glossary terms are stored in your workspace and retrieved when they match new work, which is how the product improves with use. They are never used to train our translation engine, and no other workspace can reach them.

Who at SpectrHQ can access our documents?

Access to customer content is limited to a minimal set of authorised personnel, and only where operationally necessary. Its not open to the wider team.

Where is our data processed?

On infrastructure SpectrHQ operates and controls, on SOC 2 Type II certified providers. We share specifics, including processing locations, during security review.

What happens to our files at the end of the retention period?

They are permanently deleted from storage. You can also delete a file at any point before then.

Can we get a data processing agreement?

Yes. A DPA is prepared if requested Enterprise agreements. Contact us to start the review.

Will you complete our security questionnaire?

Yes. Send it with your demo request and we will work through it directly.

Do you have SOC 2?

Our programme is under way, with Type II expected in 2027. Current security materials are available during procurement.

Security review

Bring us your requirements

Send your questionnaire, your DPA, or your list of concerns. We will answer them directly rather than pointing you at a policy page.