Security

Enterprise security you can verify, on your infrastructure or ours.

Source code

You can read all the source code, and your company can always run it itself for free forever. Audit every line, and patch on your schedule, not a vendor’s.

Deployment

Self-host on your own infrastructure, on prem or in your cloud. Or get a dedicated instance from ModelFront, with backups, monitoring, support and an SLA, at cost. Your data lives where you run it.

Data ownership

Your content, translation memories, terminology, workflows and settings stay under your control. Export everything in open formats, or move it with MCP.

AI data handling

Bring your own model keys. Content goes only to the AI vendors you configure, under your own terms with them. Self-hosted, nothing leaves your environment. ModelFront AI is optional.

Access

SAML single sign-on with your identity provider, multi-factor authentication, and fine-grained roles for people, MCP and the API.

Audit log

Every change is recorded: who, what and when, across the UI, MCP and the API. Export it to your SIEM.

Encryption

Encrypted in transit with TLS and at rest with AES-256, including backups.

Compliance

Enterprise hosting is GDPR-compliant, like the rest of ModelFront, with a DPA on request. SOC 2 and ISO 27001 are in progress. Self-hosted deployments inherit your own controls and certifications.

Vulnerability disclosure

Found something? Email security@openloc.com. We acknowledge reports and ship fixes in the open repository.