Trust & Security

Your AI data,
under your control.

Translayer is a US-incorporated independent legal entity built for frontier-AI procurement standards. This page summarizes our six hard commitments, our five-layer verification framework, and our direct answers to China-link concerns.

6 Commitments Legal Structure 5-Layer Verification China-link Certifications Red Lines Contact
If you only read one section

Six commitments.
Not slogans — hard answers.

Each commitment below maps to specific, verifiable operational actions. If any cannot be independently verified, we want to hear about it.

01Entity
Independent US entity
Translayer, Inc. is a US-incorporated independent legal entity. Contracts, banking, insurance, tax, board, and employment all sit under US law. The China-based parent does not hold customer contracts.
02Residency
Data stays in your region
Storage location is selected by the customer (AWS / GCP / Azure US or EU regions). Customer data never enters servers or devices inside mainland China.
03Zero copy
No master copy retained
In VPC / self-hosted mode, raw data lives in your environment. Translayer does not keep a master copy. Project closure triggers a verified deletion workflow.
04Auditable
Raw logs exportable
Per-project audit logs (user ID, timestamp, object, action, IP, device fingerprint) are exportable on demand. We provide raw evidence, not summaries.
05Isolated
Project-level hard isolation
Each project gets its own IAM roles, annotator pool, and audit chain. Cross-project queries are rejected at the IAM layer, not at the application layer.
06Exit
Terminate anytime
You can end the relationship at any point. Within 30 days: all data returned, all derivatives (gold sets, calibration samples) destroyed, and a destruction certificate issued.
Verification Framework

Five layers. Every layer auditable.

Most vendors say "we have SOC 2 and we encrypt." That's necessary but not sufficient — encryption protects data at rest, but AI training data is rarely at rest. Our framework covers what data actually does, end-to-end.

¹
Architecture
Where data physically lives
Customer-chosen cloud region. VPC / on-prem deployment options. No "master copy" on our side. Mainland-China regions architecturally prohibited.
²
Lifecycle
Every handler controlled
RBAC with time-bound access. VDI-only workflows. Device controls via MDM. Workspace constraints (no copy/download/screenshot).
³
Audit Evidence
Raw, not summarized
Full event logs (who/when/what/from where). Customer-readable retention. SIEM integration. Third-party auditor access on request.
Retention
Verified destruction
30-day default destruction. Grace period for rework. Destruction certificate. Backup-tier deletion verified by independent reviewer.
Workforce
Every contributor known
Identity verification. Ongoing monitoring. Anti ghost-worker controls. Per-project residency restrictions enforceable at SOW level.
Directly · Without Detour

On the China-link, we answer directly.

We acknowledge it: Translayer's parent, Sunyu Group, is headquartered in Nanjing, China. We don't sidestep this — we address it with four defenses: legal structure, technical control, contractual commitment, and verifiable evidence. Here are the three questions we hear most.

Will Chinese intelligence or data laws force Translayer to hand over customer data?
No. The PRC National Intelligence Law and Data Security Law apply to "organizations and citizens within the territory of the People's Republic of China." Translayer, Inc. is a US-incorporated independent legal entity, outside that territorial scope. Customer data physically and logically never enters China, so the Cross-Border Data Transfer Assessment is also not triggered. This is locked into a "data residency clause" in every SOW, backed by indemnity.
Can the Chinese parent use shareholder power to force a data handover?
No. Under US corporate law, directors owe fiduciary duties to the company and cannot breach contractual obligations to customers. A forced handover would mean a breach of SOW, personal director liability, and corporate liability. We add three more controls: independent directors on the board, dual-CSO sign-off for any abnormal data access request, and an obligation to proactively notify the customer within 24 hours of any such request.
Will my data be seen by people of Chinese nationality?
You decide. The compliance variable is not nationality — it's residency and contracting jurisdiction. Your SOW can specify a residency whitelist (e.g., US / EEA / UK / CA / AU / JP only). System-level enforcement: accounts bound to residency, mainland-China IPs blocked at login, residency change requires re-approval. Annotator residency distribution per project is available as a verifiable report.
Data Path · None of it touches China

From ingestion to destruction.

01 · Ingestion
Customer cloud direct
S3 / API / SFTP endpoints chosen by you; keys held in your KMS.
02 · Storage
Customer-chosen region
AWS / GCP US or EU regions, AES-256 at rest, project-isolated buckets.
03 · Annotation
VDI-controlled browser
Vetted annotators (residency whitelist), no local data, no clipboard egress.
04 · Delivery
Hash-verified handoff
Manifest + SHA-256 + contributor hash list returned to your environment.
05 · Destruction
30-day default
Original + derivatives + backups destroyed; certificate issued.
Certifications & Frameworks

External proof,
not internal claims.

Certifications don't guarantee absolute security — but they prove we're willing to be continuously examined by independent third parties.

ISO 27001
Information Security
ISO 17100
Translation Services
ISO 18587
MT Post-Editing
ISO 9001
Quality Management
ISO 13485
Medical Device QMS
SOC 2 II
Security · Availability
In Audit
Mapped internally to NIST AI RMF and NIST SP 800-53. HIPAA BAA available per project. EU AI Act Article 10 training-data governance in place (Data Sheets · bias detection · provenance chain).
Our Own Boundaries

What we actively refuse to do.

To avoid potential legal or geopolitical conflicts, we proactively decline the following categories of work. Clear boundaries protect customers and employees alike — and they keep the work we do clean.

EAR / ITAR controlled technology US export-controlled military or dual-use technical data. We identify and decline at the BD stage.
US federal classified / SCI Projects requiring Security Clearance. Recommend FedRAMP-High licensed providers instead.
Sanctioned entities (OFAC SDN, Entity List) KYC screening before contract; any match results in immediate decline.
Election & political influence Political parties, campaigns, and political-ad targeting are out of scope.
Weapons of mass destruction AI data related to nuclear, biological, or chemical weapon development — unconditional refusal.
CSAM & non-consensual biometrics Child sexual abuse material; unauthorized face / biometric scraping — unconditional refusal.
"Trust isn't built on promises — it's built on evidence you can independently challenge. Every claim on this page maps to a file you can read, a system you can log into, or a test you can run."
Open Door

Bring your security, legal,
and compliance teams.
Challenge any claim on this page.