Security at Smartling
Smartling complies with PCI, SOC 2, HIPAA, and GDPR standards. Learn more about our certifications below.
Certified security, so you can focus on growth
What sets us apart
PCI
Certifies presence of best security practices for secure processing and transmission of credit card data. Smartling has continuously maintained PCI Level 1 compliance since 2012.
SOC 2
Certifies a third-party vendor’s controls over security, availability, processing integrity, and confidentiality or privacy. Smartling has continuously maintained compliance with SOC 2 standards since 2013.
HIPAA
Certifies an external vendor’s controls over privacy and security of certain health information covered by the law. Smartling has maintained HIPAA compliance since 2013.
GDPR
Protecting personal data in the EU, Smartling has met GDPR’s strict security and privacy standards since its introduction in 2018.
ISO
Certifies industry-specific compliance with security standards. Learn more about each certification below.
Privacy Policy
Learn how we protect your personal data and ensure compliance with global security standards.
ISO-certified translations you can trust
Our commitment to quality and security is backed by ISO certifications. Learn more about our standards for translation excellence, medical device compliance, quality management, and machine translation post-editing:
FAQs
Smartling maintains strict control over personal data that passes through its systems at all times while remaining committed to data security. In light of evolving data privacy standards throughout applicable law across jurisdictions—particularly in the EU area—Smartling is happy to share the below statement of policy and practice with its customers and prospective customers. For more information, please view Smartling's privacy policy.
- Productivity tools and cloud data storage, including, for some customers, CMS connector products to move untranslated content into Smartling’s productivity tool and translated content back out to customers (the “Smartling Platform”);
- A web proxy that intercepts Smartling customers’ end users’ HTTP requests and returns translated content stored in the Translation Platform (the “Global Delivery Network” or “GDN”); and
- A translation services marketplace to facilitate purchase of translation services by Smartling end users from independent translation service providers. Many of our customers do not use all of these products. If your firm does not use the GDN, or if it relies on other vendors for translation services, you need not worry about Smartling’s handling of those types of personal data.
Smartling interacts with personal data in four major contexts: transmission through Smartling infrastructure, Smartling account maintenance/use, outbound marketing communications, and communications between Smartling and Smartling personnel.
Transmission Through Smartling Infrastructure – Smartling makes a concerted effort during each customer’s onboarding and throughout their relationship to segregate personal data and prevent it from entering the Smartling Platform.
Smartling Customer Records – As a matter of course, Smartling must create and maintain files on each of its customers, including personal information belonging to customer representatives that interact with Smartling’s products. This includes names and contact information, but also billing information for the customer, as well as login and password information, among other potentially identifying data points.
Outbound Marketing Communications – Smartling sends marketing communications to its customers and others, and it maintains lists of contact information to that end.
Because we are keenly aware of the risks associated with personal data, Smartling is happy to work with its customers to ensure data security, proper handling of personal data, and privacy.
Smartling assumes full responsibility for its handling of personal data. Our standard agreements make clear that Smartling assumes responsibility for its employees, contractors, and suppliers in this and every other compliance area. We take time out of our onboarding process to work with our customers to help prevent the mistaken transmission of personal data into channels where it does not belong.
Smartling relies on industry-leading cloud services to keep data secure and compliant. Smartling uses Amazon Web Services locations across the globe to house customer data, largely because of the risks associated with data crossing jurisdictional boundaries.
Smartling relies on independent contractors. Smartling employs a number of independent contractors to provide services throughout its business. Because Smartling relies on these vendors to maintain its service standards, we cannot agree to allow our customers special control over these vendors’ assignments or provide lists of these contractors.
Smartling works with its customers to ensure compliance. Because we know that each customer’s situation is different, should the need arise, Smartling’s team is happy to work with customers to ensure that every one of our customers has what they need to use Smartling with confidence. Contact your sales representative or account manager if you have any additional concerns about using Smartling.






