Your translation data and API keys are protected with enterprise-grade security measures. Here's how we keep your data safe.
Your data is encrypted both in transit and at rest.
All API requests use TLS 1.2+ encryption. Data is never transmitted in plaintext.
All data stored in our databases is encrypted using AWS-managed encryption keys (AES-256).
All requests pass through AWS API Gateway which enforces HTTPS and provides DDoS protection.
Secure authentication with multiple layers of protection.
User authentication powered by AWS Cognito with support for email/password and OAuth (Google, GitHub).
Minimum 8 characters with uppercase, lowercase, numbers, and special characters required.
All accounts require email verification before activation.
JWT tokens with short expiration times. Refresh tokens allow seamless re-authentication.
Your API keys are generated securely and can be revoked at any time.
API keys are generated using cryptographically secure random bytes (256-bit entropy).
Revoke your API key instantly from your dashboard. Revoked keys are immediately rejected.
Regenerate your API key at any time. The old key is automatically deactivated.
Keys use the sk_live_ prefix for easy identification and to prevent accidental exposure.
Protection against abuse and unauthorized access attempts.
Request limits based on your plan tier (Free: 10/min, Starter: 60/min, Pro: 300/min).
Every response includes X-RateLimit-Remaining so you can monitor usage.
Failed authentication attempts are logged for security monitoring.
Strict CORS policy allows only whitelisted origins to access the API from browsers.
Your translation data is handled with care and clear retention policies.
Cached translations are automatically deleted after 90 days of inactivity.
We never sell your translation data or use it for training AI models.
Delete all your data instantly via API (DELETE /api/user/data). Translation keys, API keys, and profile are permanently removed.
Each user's translation data is stored separately and accessible only with their API key.
We believe in being transparent about how your data is handled.
To provide translation services, our systems must process your content. This means:
Built on AWS with enterprise-grade infrastructure security.
Lambda, DynamoDB, API Gateway, Cognito
Data stored in AWS US-East-1
Built-in DDoS protection
Real-time error tracking
If you have security concerns or need to report a vulnerability, please contact us.
team@shipi18n.com