These are the security practices behind XNN Translate (formerly StreamTranslate Studio). They are an honest description of what we actually do — we do not claim formal certifications such as SOC 2, ISO 27001, or HIPAA.
Encryption and account authentication
Traffic between your browser, the desktop app, and our servers is protected with TLS in transit. Account passwords are stored only as salted hashes, never in plain text, and sign-in uses our magic-link and account authentication flow.
Card payments are handled by Stripe, which is PCI-DSS compliant; XNN never stores your card details. Live captions, audio, and recording history are processed locally on your own device by default, so the most sensitive content never reaches our servers unless you choose to share it.
We publish downloads through documented release checks, and installers will be code-signed at release. If a security incident affects your personal data, we are committed to notifying affected customers without undue delay. Report a vulnerability to [email protected].
Documented release checks; installers signed at release