Snapshot 23432
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to content Organizational security Information Security Policy applies across the inweso organization and is mandatory for employees and contributors. Our Information Security Management System is built on three pillars: people, processes, and technology. We follow a Zero Trust Architecture mindset: “never trust, always verify”, with strict identity verification and continuous authentication. Training, access & incident response Ongoing security awareness training for employees and role-specific training where needed. Access control based on least privilege, with regular reviews and timely revocation/updates. Strong authentication mechanisms (including MFA) for internal systems where applicable. An incident response process to address, investigate, and remediate security incidents. Infrastructure & data residency We do not maintain our own server infrastructure. Customer data (translations, project metadata, account information) is hosted on Amazon Web Services (AWS) in Ireland. AWS data centers are equipped with comprehensive physical security measures. Encrypted disaster-recovery copies of translation namespaces and project configurations are additionally kept off-AWS on BunnyCDN Storage (EU), under encryption keys held offline by Locize, so the service remains partially restorable if our primary infrastructure becomes unavailable. Published translations are delivered through CDNs with edge locations worldwide (BunnyCDN for the Standard CDN, AWS CloudFront for the Pro CDN). Business email correspondence (e.g. [email protected]) is hosted in Switzerland by Hostpoint AG. App-generated notifications are delivered via Amazon SES on AWS. Locize is operated by a Swiss-registered company. Read more about our Swiss-engineered TMS and how FADP + GDPR apply. Learn more: AWS security Supplier & third‑party security We maintain vendor risk management practices and review third parties used to deliver the service. A list of sub-processors and related privacy details is available in our Privacy policy. Application security Our team keeps the application and its dependencies up to date. We use monitoring and operational practices to detect and respond to suspicious activity. Built-in security features include: Multi-factor authentication: TOTP (authenticator apps), WebAuthn (FIDO2 hardware keys), and YubiKey Single Sign-On via SAML 2.0 REST API authentication with API token permission control Role-based permissions Backups and versioning Enforced password complexity standards Authenticated encryption at rest for personal data and stored third-party API credentials Versioned signing keys for sessions, supporting zero-downtime rotation Periodic credential rotation across vendor integrations and signing keys Payments & PCI responsibilities When you subscribe to a Locize account, we do not store your billing information on our infrastructure. Payments are processed by our partner Stripe, which is compliant with PCI Security Standards. More details: Stripe security Access to customer data Access to customer data is limited to authorized employees who require it for their job (for example support). Support representatives should access only the files or settings needed to resolve customer issues. Business continuity & disaster recovery We maintain and regularly review a Disaster Recovery Plan and a Business Continuity Plan. These plans are designed to minimize downtime and support the timely restoration of critical business functions. As part of this, we keep encrypted, off-AWS disaster-recovery snapshots of translation namespaces, project configurations, and project-administrator contact details on BunnyCDN Storage (EU). They are encrypted with keys held only by Locize (BunnyCDN stores only ciphertext and cannot read them) and retained on a rolling multi-week schedule, so we can restore read access to translations even if our primary AWS account becomes unavailable. Contact & vulnerability reporting If you have questions about security at Locize or would like to submit a vulnerability report, email [email protected]. Security-related reports are treated with high priority.