We built TrustyTranslate with security as the foundation — not an afterthought. Every document you upload is encrypted, access-controlled, and permanently deleted after 30 days.
AES-256
Encryption standard
TLS 1.3
Transit security
30 days
Max. retention
AWS
Cloud infrastructure
01
At rest
Every file stored in Amazon S3 is encrypted with AES-256 — the same standard used by the U.S. Department of Defense and financial institutions. Encryption keys are managed by AWS Key Management Service (KMS) and rotated automatically.
In transit
All data moving between your browser and our servers travels over TLS 1.3. This prevents eavesdropping and man-in-the-middle attacks. We enforce HTTPS site-wide and reject plain HTTP connections.
AES-256 has never been cracked. At current computing speeds, a brute-force attack would take longer than the age of the universe. It is the encryption standard mandated by the U.S. National Institute of Standards and Technology (NIST) for protecting classified information.
02
Your documents are stored in Amazon S3 — the industry-leading object storage service trusted by banks, hospitals, and government agencies worldwide. We run entirely on AWS, which holds the following compliance certifications:
SOC 2 Type II
Security & availability
ISO 27001
Information security mgmt
FedRAMP
U.S. federal compliance
PCI DSS
Payment card security
HIPAA eligible
Health data standards
GDPR
EU data protection
How your file moves through our system
Upload
Your browser requests a short-lived pre-signed S3 URL from our server. The file uploads directly to S3 — it never passes through our web server.
Text extraction
Amazon Textract reads the file directly from S3 to detect text and count pages/words. No copy of the file leaves AWS.
Translation
Our translator accesses the encrypted file through a temporary, access-controlled link. Access is logged and automatically expires.
Delivery
The translated document is sent to your email via Amazon SES over an encrypted connection. The file remains in S3 until deletion.
Deletion
30 days after upload, an automated lifecycle policy permanently deletes the original and translated files from S3. No manual step required.
03
We follow the principle of least privilege: every person and system gets access only to what they need, for as long as they need it — nothing more.
Private S3 buckets
No document stored in our system is publicly accessible. All S3 buckets have public access blocked at the account level. Files can only be reached through authenticated, time-limited pre-signed URLs.
Expiring access links
When a translator needs to open a document, we generate a pre-signed URL that expires in 1 hour. After that, the link is dead — even if someone intercepts it.
IAM role-based permissions
Each service (upload, text extraction, translation, delivery) operates under a separate AWS IAM role with only the permissions required for that specific task. A compromise in one service cannot access another.
No third-party access
Your documents are never shared with, sold to, or processed by any third-party AI training systems, advertising networks, or data brokers. Period.
04
Day 0
You upload your document
File is encrypted and stored. Processing begins immediately.
Day 1–4
Translation is completed
Your certified translation is delivered to your email.
Day 30
Automatic permanent deletion
S3 lifecycle policy triggers. Original file, extracted text, and translated copy are permanently and irreversibly deleted. No manual step needed.
Save your translation when you receive it
Because deletion is permanent and automatic, we cannot recover files after the 30-day window. We strongly recommend saving your translated document as soon as you receive it by email. If you need an early deletion, email us at support@trustytranslate.com — we will process it within 48 hours.
05
We never see, store, or touch your credit card details. All payments are handled entirely by Stripe, a PCI DSS Level 1 certified payment processor — the highest certification available in the payments industry.
Card data isolation
Your card number is tokenized by Stripe before it ever reaches our servers. We only receive a token — never the actual card number.
Zero card storage
We do not store any payment data in our database. Our systems never process raw card details at any point.
Fraud protection
Stripe's fraud detection system, Radar, monitors every transaction in real time and blocks suspicious activity automatically.
06
We take security reports seriously. If you discover a vulnerability in our systems, please report it responsibly and we will respond promptly.
How to report
Email us at security@trustytranslate.com
Include a clear description of the vulnerability
Provide steps to reproduce the issue
Do not publicly disclose before we respond
Our commitment
Acknowledge your report within 48 hours
Keep you informed as we investigate
Fix critical issues within 7 days
Credit researchers who report responsibly
Related Policies