Features Use Cases Pricing FAQ Guide
Log In Start Free

Security

Last updated: 28 February 2026


1. Overview

Security is foundational to LingoVoice. We protect your data at every stage — from the moment audio leaves your microphone through real-time translation and back to your speakers. This page provides a transparent overview of the technical and organisational measures we employ to safeguard your information.


2. Encryption

2.1 In Transit

All connections to LingoVoice are secured with TLS 1.2 or higher. This applies to every communication channel:

No unencrypted data transmission is permitted at any point in the platform.

2.2 At Rest

All platform data is stored on encrypted volumes provided by DigitalOcean block storage. Data remains protected even in the event of physical media compromise.

2.3 Passwords

User passwords are hashed using bcrypt with 12 salt rounds. Passwords are never stored in plaintext or reversible formats. bcrypt's adaptive cost factor ensures resistance to brute-force attacks as hardware capabilities improve.


3. Authentication & Access Control

3.1 JWT Tokens

3.2 OAuth

LingoVoice supports sign-in via Google and Microsoft OAuth. For OAuth users, no password is stored on our platform — authentication is delegated entirely to the identity provider.

3.3 Organisation Roles

Organisations on LingoVoice use a role-based access control model with three tiers:

3.4 Guest Tokens

Guest access is controlled through purpose-built tokens that are:


4. Data Handling


5. Infrastructure


6. Rate Limiting & Abuse Prevention

LingoVoice employs Redis-backed rate limiting across all API endpoints to prevent brute-force attacks, credential stuffing, and platform abuse:

Endpoint Category Limit Window
Authentication (login, register) 10 requests 15 minutes
Translation API 20 requests 1 minute
Password reset 3 requests 1 hour
General API 500 requests 15 minutes

Additional abuse prevention measures include:


7. Sub-processors

LingoVoice engages third-party sub-processors to deliver translation, speech, payment, and infrastructure services. All sub-processors are bound by data processing agreements that require them to protect personal data in accordance with UK GDPR.

For the complete sub-processor list with data shared, hosting locations, and certifications, see our Data Processing Agreement.


8. Incident Response

LingoVoice maintains a documented incident response process. In the event of a personal data breach:

To report a security vulnerability or concern, contact security@lingovoice.ai.


9. Contact

For security questions, vulnerability reports, or to request further details about our security practices, please contact us:

Security Enquiries

Email: security@lingovoice.ai

Data Protection Officer

Email: dpo@lingovoice.ai

General Support

Email: support@lingovoice.ai

Lingo Service Translations, Cardiff, United Kingdom