Skip to content

Trust

Security

Last updated: 11 August 2026

  • Only slide text reaches the AI provider, never your file.
  • Every upload is scanned for malware.
  • Sign-in is handled by Google Firebase.
  • Files are encrypted at rest in Doha, Qatar.
  • No analytics, trackers, or advertising technology.

1. How your presentation is processed

Your browser uploads the file directly to Google Cloud Storage using a short-lived signed link. The file does not pass through our application servers on the way in.

The file arrives in a quarantine location and is scanned for malware. Only a file that passes the scan is moved to the working location where it becomes available for translation.

Our translation engine opens the file and extracts its text. Only that text, and the glossary terminology that applies to it, is sent to the translation provider. The file itself, its images, and its embedded media do not leave our infrastructure.

The translated presentation is written back to storage and a PDF preview is rendered. Both are accessible only to you and to the members of the team the presentation belongs to.

2. Where your data is held

All files, previews, and database records are held in Google Cloud's me-central1 region in Doha, Qatar. Our application servers operate in the same region.

Translation is the exception. Slide text is sent to OpenAI, which processes it outside the region.

3. Encryption

Traffic between your browser and the service is encrypted using TLS. HTTPS is enforced with HSTS, so a browser that has visited the service once will refuse an insecure connection to it.

Files in storage and records in the database are encrypted at rest using Google-managed keys.

The database has no public address and is reachable only from within our own network.

4. Access control

We do not store passwords. Authentication is handled by Google Firebase, which holds your credentials.

Every request is authorised on the server against your identity and your team and organisation membership. Hiding a control in the interface is a convenience, not a boundary. The authorisation check is performed on the server for every request.

Organisations that need their members to sign in through their own identity provider can arrange this with us.

Links used to download or preview a file are signed and expire within minutes.

5. AI provider controls

OpenAI does not use data submitted through its API to train its models unless a customer explicitly opts in. We have not opted in.

OpenAI retains API content for a limited period for abuse monitoring, after which it is deleted.

6. Application security

A Content Security Policy restricts what the application may load and where it may connect. The application cannot be embedded in a frame on another domain.

Uploads are limited by size and validated structurally before processing. Deliberately malformed presentations are rejected rather than allowed to disrupt the pipeline.

Uploaded fonts are parsed and validated before storage, and are rejected where their embedding permissions do not allow it.

Each service runs as a non-root user in its own container. Secrets are held in Google Secret Manager and are not stored in our source code.

7. Service providers

We use a deliberately small number of providers. This is the complete list.

Google Cloud provides hosting, storage, the database, and authentication through Firebase, in Doha, Qatar.

OpenAI provides translation and receives slide text only.

Resend transports in-app support messages, and Microsoft 365 hosts the support mailbox where those messages and optional screenshots are handled.

8. Resilience

The production database is backed up automatically every day, and backups are retained for 14 days. Files are held in Google Cloud Storage, which stores redundantly within the region.

If your procurement process needs detail on our recovery arrangements, write to info@theagileworx.com and we will set them out.

9. Reporting a vulnerability

If you believe you have identified a security issue, write to info@theagileworx.com with sufficient detail for us to reproduce it. We aim to acknowledge reports within one business day.

Research conducted in good faith is authorised under our Terms of Service. Keep to your own accounts and data, do not degrade the service for others, and allow us a reasonable opportunity to resolve the issue before disclosing it publicly.