TRUST MARKERS
Responsible AI
How we process client data
Where data lives
Data is primarily hosted in Microsoft Azure UK/EU regions, with backup and resilience across the EEA. Access is protected by MFA and secure channels.
Who can access it
Access is strictly role-based (least privilege), reviewed regularly, and revoked immediately when people change roles or leave. Privileged accounts are monitored.
How we protect it
Strong encryption for data at rest (AES-128 minimum; AES-256 for sensitive data) and in transit (TLS 1.2+; FIPS 140-2 compliant modules). System logging and monitoring are enabled for critical systems.
How long we keep it for
Retention and disposal follow documented policies for secure handling and cryptographic erasure/wiping prior to reuse or disposal.
What sets GAI Translate apart
Incident response & continuity
We operate formal incident reporting with root-cause analysis, corrective actions, and prompt client notification via predefined protocols. Business continuity and disaster recovery plans are documented, tested, and regularly updated, with defined RTO/RPO and alternate-site arrangements; encrypted backups are routinely tested for recovery.
Roadmap (enterprise trust building)
We’re pursuing further independent attestations and technical transparency to support regulated buyers: publishing a maintained Subprocessors & Data Flows registry, detailed Encryption/Key Management notes, Pen-test summaries, Cyber Essentials (or CE Plus) assessments, and ultimately SOC 2 Type II reports for enterprise buyers (especially in the US).
Client FAQs
Please email [email protected] (subject: “Security”), and we will route your request to the security team.
AWARDS AND CERTIFICATIONS



















