"Enterprise-grade security" is not a product tier. It is a set of answers a translation vendor can either give in writing or cannot. For sensitive financial records, six answers carry most of the weight: a certification scope statement that names the translation service itself rather than the corporate network, encryption specifics including who holds the keys, an access model scoped to the document rather than the account, contractual retention and no-training terms, a named sub-processor list, and an incident-notification clock measured in hours. A vendor who answers those precisely is credible. A vendor who answers with logos and adjectives has told you something too.
This guide walks the questions that actually land in a translation vendor's inbox during procurement, what a substantive answer looks like, and what the evasive version of the same answer sounds like when you are reading forty of them.
The Questionnaire Is a Test of Specificity
Security questionnaires are rarely won or lost on whether a control exists. They are decided on whether the vendor can describe the control without hedging. Someone who runs the system says "TLS 1.2 or higher, AES-256 at rest, keys in a managed KMS with rotation every 90 days, and we do not hold plaintext outside the processing window." Someone reading from a marketing page says "bank-grade encryption, end to end."
That difference is diagnostic, and it is why the useful reading strategy is grammatical rather than technical. Count the nouns. Substantive answers name systems, versions, roles, regions and durations. Evasive answers name feelings. When a control genuinely does not apply, the good answer says so and explains the compensating control — which is a stronger signal than a vendor claiming every control on the sheet, because nobody has every control.
Certification Scope Statements Beat Certification Badges
The single most common procurement mistake is treating a certification as binary. ISO/IEC 27001 certifies an information security management system within a declared scope, and that scope is a written statement listing the locations, services and systems covered. A vendor can hold a genuine certificate whose scope covers head-office IT and excludes the translation platform entirely.
So ask for three artefacts, not one: the certificate, the Statement of Applicability, and the scope statement itself. Read the scope for the name of the product you are buying. The same test applies to SOC 2 — a Type II report over a defined observation period is evidence; a Type I is a point-in-time design opinion; a "SOC 2 compliant" claim with no report at all is a sentence. Where machine learning is in the pipeline, ISO/IEC 42001 covers AI management systems and is beginning to appear on questionnaires alongside the older two. Same rule: scope first. We cover how these standards differ in ISO certified translation services.
Encryption Answers Have Four Parts
"Encrypted in transit and at rest" is the answer everyone gives. The follow-ups separate the field.
In transit. Which TLS versions are accepted, and are older versions refused rather than merely deprecated? Does that include internal service-to-service traffic, or only the browser-facing edge?
At rest. Which cipher, applied at which layer — full-disk, object store, or field level? Full-disk encryption protects against a stolen drive and very little else.
Key management. Who generates, stores and rotates keys? Is there a customer-managed key option, and if not, which internal roles can access key material?
Processing. A file must be decrypted to be translated. Ask where that happens, how long plaintext exists in memory or temporary storage, and whether temporary artefacts are encrypted too.
The fourth question is the one that gets skipped, and it is the one that matters most for a board pack.
Access Control Answers Should Name Roles
The question on the form is usually "describe your access control model." The answer worth having names the roles and the boundary.
Look for role-based access with least privilege as a starting point, then push into specifics. Can a vendor support engineer open a customer document, and under what process — standing access, or break-glass with approval and an expiring grant? Is customer data segregated by tenant at the storage layer or by an application-level filter? Is administrative access to production gated behind SSO with enforced MFA, and does the vendor support SSO and SCIM provisioning on your side so that your own leavers lose access automatically?
An answer that describes internal roles honestly, including the fact that some engineer somewhere can be granted access under a documented process, is more trustworthy than "no employee can ever see your data," which is almost never true and rarely survives a follow-up question.
Retention, Training and Deletion Belong in the Contract
Retention is where documentation and contract diverge most often. The docs page says files are deleted after processing; the DPA says the vendor may retain content as necessary to provide the service. Only one of those is enforceable.
Ask for four commitments in the agreement itself. First, the retention period for the uploaded source file and for the translated output, stated as a duration. Second, an explicit statement on whether submitted content is used to train or improve models, including any human review pathway. Third, whether deletion is available on request and whether it can be triggered through the API rather than a support ticket. Fourth, whether deletion covers derived artefacts — extracted text, OCR output, caches, queue payloads — or only the original upload.
For material with a defined confidentiality obligation, such as audited financial statements crossing borders, the derived-artefact question is not pedantry. It is the whole answer.
Sub-processors and Where Processing Happens
Every translation service of any scale has sub-processors, and a service that routes to an upstream model provider inherits that provider's retention and residency posture whether or not the questionnaire mentions it. The substantive answer is a maintained list: entity name, role, processing location, and a notification mechanism for changes.
Residency questions should be answered by region, not by continent. "EU" is not an answer if the vendor's inference runs elsewhere; ask which region performs each processing step, including any fallback region used during a failover. Under GDPR, onward transfers carry their own obligations and the transfer mechanism should be named rather than gestured at.
A vendor who declines to name sub-processors under commercial confidentiality has effectively told you they cannot support your Article 28 obligations, which is useful information delivered inconveniently. Bluente publishes its posture for exactly this reason — see GDPR compliant document translation.
Incident Response Measured in Hours
The incident-response section of a questionnaire attracts more aspiration than any other. Everyone has a plan. Fewer have a clock.
Push for four numbers and one document. The notification window for a confirmed breach affecting your data, expressed in hours from confirmation and written into the contract. The definition of "confirmed," because a vendor who starts the clock at internal certainty rather than reasonable suspicion has a much longer runway. The escalation path and the named contact who will actually call you. The date of the last tabletop or incident exercise. And the post-incident report format you will receive.
Then ask a question that is rarely on the form: has the vendor had a security incident affecting customer data, and what changed afterwards? A vendor with a clear-eyed answer about a past incident and the remediation that followed is usually a safer bet than one claiming an unblemished record.
Sorting Substantive Answers From Evasive Ones
After enough questionnaires, the tells are consistent.
Deflection to a framework. "We follow NIST guidance" answers nothing. The NIST AI Risk Management Framework is voluntary and non-certifiable; alignment with it is a claim, not an attestation.
Answering a different question. You asked about retention of derived artefacts; the answer describes upload encryption.
Documentation as evidence. A link to a public help page is not a contractual commitment, and help pages change without a change notice.
Certification without scope. Covered above, and worth repeating because it is the most expensive single miss.
Refusal framed as security. "We cannot share our sub-processor list for security reasons" is a category error; sub-processor lists are a transparency control, not an attack surface.
Practitioners compare notes on this in a thread on using AI with confidential documents, where the recurring conclusion is that vendors who answer quickly and specifically tend to be the ones running the controls themselves. It is a crude heuristic. It is also a good one.
A Half-Day Test Before Signing
Before the commercial conversation closes, run a short evidence exercise. Request the certificate plus scope statement plus SOC 2 Type II report under NDA, and read the scope line for your product's name. Request the sub-processor list and the DPA, and check that retention, training and deletion appear in the DPA rather than only in help articles. Send one representative file — a redacted quarterly pack is ideal — and ask the vendor to describe, step by step, every system it will touch and how long each holds a copy.
The last exercise is the one that produces the most information per minute. A vendor who can narrate the path of a single file through their own stack, naming each hop, is a vendor who has thought about it. Anyone else is reading the same page you already read. If you are also evaluating general-purpose assistants for this work, the same test applies — see is Gemini safe for confidential documents.
Sources and Further Reading
How to use AI on confidential documents without leaking them — founders and operators comparing what vendors will and will not put in writing
Related Reading
Last reviewed 24 August 2026 by the Bluente document engineering team, who build and test the pipeline described here. We update these guides when the underlying standards, regulations or file formats change.
Send us the questionnaire — we answer with scope statements, not logos. Talk to the Bluente team.