SECURITY

Security controls across Cloud and WordPress.

Languvia separates commercial administration, customer workspaces and signed WordPress connector traffic.

API-key and provider security

Translation-provider credentials are encrypted at rest, returned only when initially created where necessary, and can be rotated through the commercial control plane. WordPress connector secrets are also encrypted and requests use timestamped HMAC signatures with nonce replay prevention.

Incident and email-domain controls

Languvia includes incident records and a public status surface, plus operational SPF, DKIM-selector and DMARC checks for the configured lifecycle-email domain.

Tenant isolation

Customer APIs derive tenant identity from the authenticated session rather than browser-supplied IDs.

Connector authentication

WordPress requests use timestamped HMAC signatures and nonce replay protection.

Encrypted credentials

Provider and connector secrets are encrypted at rest and not returned through ordinary API reads.

Session controls

Admin and customer sessions are separate and can be revoked.

Audit trail

Commercial administration, execution and security events are recorded for operational review.

Execution controls

Global and per-site emergency pause controls can stop translation execution.