Trust & Security

Your files are the product. Protecting them is the job.

What we do today, stated plainly — and what is on the roadmap, stated just as plainly. No checkbox theater.

Last updated: August 3, 2026

Encryption

  • All traffic is encrypted in transit with TLS 1.2+.
  • Customer content is encrypted at rest on our storage layer.
  • Enterprise plans can bring their own encryption keys (customer-managed KMS) for storage at rest.

Your content never trains models

Translation runs on frontier AI models accessed through provider APIs under terms that exclude training on our traffic. We do not use your files, glossaries, or translation memories to train models — ours or anyone else's. Your Golden TM is scoped to your organization and is never shared across tenants.

Portal-only delivery — no email attachments

Translated deliverables are never sent as email attachments. Notifications link to the authenticated portal, and files are downloaded from there. This is a deliberate compliance measure: content doesn't sit in mail servers, forwarding chains, or inbox archives outside your control.

Access control

  • Role-based access inside each organization: admins, project managers, and reviewer accounts.
  • Reviewer accounts (for your client's own editors) see only the jobs explicitly assigned to them — never your other clients, volumes, or configuration.
  • All data access is scoped per organization at the query layer.

Retention and deletion

Source and output files are retained so you can re-download deliverables, then purged on a configurable retention window. Organizations can request earlier deletion of specific jobs at any time through their Account Manager.

Infrastructure

  • Inbound machine-to-machine traffic is signed and IP-allowlisted.
  • Daily encrypted backups with off-site copies.
  • Data residency (EU or US processing) and dedicated worker pools are available as Enterprise options, along with on-prem deployment for the most sensitive workloads.

Compliance — what's real today

  • GDPR: we operate as a processor for the content you upload; see our Privacy Policy.
  • HIPAA: HIPAA-aligned safeguards (encryption, access scoping, portal-only delivery, audit trail). Business Associate Agreements are available on Enterprise plans.
  • SOC 2:not certified yet — we say this plainly. A readiness program aligned to SOC 2 controls is in progress; ask us for the current status and we'll show you where we are, control by control.

Reporting a vulnerability

Found something? Write to security@fily.pro. We read every report and respond fast — and we'd rather hear it from you than not hear it at all.