Security & privacy

    Security built around the document

    Translate contracts, filings, reports and internal records without turning them into training data or unmanaged copies. Bluente encrypts every file, limits retention and gives enterprise teams control over access, processing and deployment.

    Trusted by teams at
    Franklin TempletonLaSalleKearneyYaraShimadzu

    Confidential from upload to deletion

    Your document should not become somebody else’s dataset, sit indefinitely in a processing queue or survive in a forgotten download folder.

    AES-256 encryption at rest

    Files are protected with AES-256 encryption at rest and encrypted in transit. Access to production data is restricted, and the processing path is documented for enterprise review.

    Never used to train shared models

    Your documents, corrections and glossary content are not used to train Bluente or third-party shared models. Private model training is a separate, explicit engagement.

    Zero data retention

    Files are not retained for training or reuse. Transient uploaded and generated files are automatically deleted within 24 hours, with stricter controls available for enterprise deployments.

    One controlled path through the translation

    Bluente protects the file as a document, not just the text extracted from it. The same controlled workflow covers OCR, translation, terminology, reconstruction and delivery.

    The document enters encrypted and returns intact

    A contract, spreadsheet, presentation or scan enters through an encrypted connection. Bluente processes only what is required to translate and reconstruct it, then returns the finished file with its tables, numbering, comments and layout preserved.

    • Encryption in transit and at rest
    • No document content used for shared-model training
    • Zero data retention, with transient files deleted within 24 hours
    • Formatting and document structure preserved through processing
    Review our security posture
    Confidential documentcontrolled path
    Encrypted in
    Encrypted out

    Access follows your organisation’s rules

    Give people the translation access they need without creating a second identity system or a shared-account workaround.

    Enterprise sign-in

    Connect SAML or OIDC single sign-on to your existing identity provider. Require multifactor authentication for users outside SSO.

    Roles and workspaces

    Use role-based permissions and separate workspaces to keep business units, matters and document sets within the boundaries you define.

    Auditable activity

    Audit logs cover uploads, downloads, administrative changes and retention events, giving security and compliance teams evidence they can review.

    Assurance your reviewers can verify

    The proof belongs in reports and contractual documents, not in an unsupported security claim.

    SOC 2 compliant — Type I

    Our Type I report assesses the design of controls covering the security, availability and confidentiality commitments relevant to the service.

    ISO/IEC 27001

    An information-security management system structured around defined controls, responsibilities and continuous risk management.

    GDPR-ready contracting

    Data Processing Agreement, EU Standard Contractual Clauses and a documented subprocessor chain for cross-border processing review.

    Choose where documents are processed

    The security model stays consistent; the operational boundary changes to match your policy.

    DeploymentProcessing boundaryBest suited to
    Multi-tenantBluente-managed environment, workspace-isolated, region-pinned and automatically deleted within 24 hoursMost enterprise teams, including regulated workflows cleared for managed cloud processing
    Single-tenantA dedicated Bluente-managed instance isolated from other customersOrganisations requiring dedicated infrastructure and scheduled change control
    Your own cloudYour AWS or Azure tenancy; documents remain inside your accountPolicies requiring customer-controlled cloud infrastructure
    On-premiseInside your network with no document content sent outside the perimeterClient mandates or institutional rules that prohibit external processing

    Keep processing inside your environment

    Where policy does not permit managed-cloud processing, Bluente can run as the document layer around models your institution already hosts and has already approved.

    Your models. Your network. The document returned intact.

    Your approved model handles language inside your environment. Bluente handles OCR, parsing, terminology, tables, clause numbering, reconstruction and quality checks around it. Document content stays within the boundary you control.

    • Dedicated instance, your own cloud or fully on-premise
    • Runs against models already approved by your organisation
    • Architecture and deployment documentation supplied for review
    • Hardened container images for customer scanning and provenance checks
    Explore private deployment
    Inside your environmentyour approved models
    Documents
    Stay inside

    Ready for security and procurement review

    Get the service detail needed to make a decision without translating marketing language into a control assessment.

    Architecture and data flow

    Processing locations, system boundaries, retention behaviour and deployment diagrams supplied for technical review.

    Subprocessors and contractual controls

    Provider chain, data-processing terms, Standard Contractual Clauses, audit rights and incident-notification provisions documented up front.

    Exit and portability

    The treatment of your documents, terminology, training material and any private model is agreed before deployment rather than discovered at renewal.

    Frequently asked questions

    Are our documents used to train AI models?
    No. Documents, glossary content and reviewer corrections are not used to train Bluente or third-party shared models. Training a private model for your workspace is a separate, explicit engagement.
    What does zero data retention mean?
    Documents are not retained for model training, product improvement or reuse. Transient uploaded and generated files are automatically deleted within 24 hours. Private deployments can apply stricter controls inside the customer-managed environment.
    How is data encrypted?
    Files are protected with AES-256 encryption at rest and encrypted in transit. Detailed architecture and processing information is available during enterprise security review.
    Can we control where processing happens?
    Yes. Processing region can be pinned, and Bluente supports multi-tenant, single-tenant, customer-cloud and on-premise deployment options.
    Do you support enterprise identity management?
    Yes. SAML and OIDC single sign-on, multifactor authentication for non-SSO users, role-based permissions and separate workspaces are supported.
    What can administrators audit?
    Audit logs cover uploads, downloads, administrative changes and retention events.
    Which compliance documents are available?
    Bluente is SOC 2 compliant with a Type I report and maintains ISO/IEC 27001 assurance, with GDPR documentation, EU Standard Contractual Clauses and subprocessor information available for review.
    Can Bluente run entirely inside our network?
    Yes. See private deployment for dedicated, customer-cloud and on-premise options, including deployment around models your organisation already hosts.

    Translate the document. Keep control of the data.

    Bring your security requirements and one representative file. We will show you the processing path, the evidence and the deployment option that fits.