Trust & Security Center
Enterprise-grade security, GCC data residency, and transparent sub-processor commitments.
GCC Data Residency
We understand the strict requirements of the UAE PDPL and Saudi SDAIA. All client data, including translation proxy caches and widget telemetry, is processed and stored exclusively within secure GCC cloud regions (UAE/KSA).
Zero PII Architecture
AccessiLens AI is designed from the ground up to never collect, store, or transmit Personally Identifiable Information (PII). Our widget operates entirely on the client's DOM, and our backend analytics redact all sensitive strings.
Sub-processor List
To provide our services, AccessiLens utilizes the following trusted infrastructure partners. We execute strict Data Processing Agreements (DPAs) with all sub-processors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud (GCP) / Firebase | Hosting, Authentication, and Database | Middle East (me-central1 / me-central2) |
| Stripe | Payment Processing | United States / Global |
| OpenRouter AI | Machine Translation Inference | United States |
Compliance Readiness
While we do not publicly distribute detailed penetration test reports or SOC 2 documentation to prevent reconnaissance attacks, these documents can be made available to enterprise procurement teams under an NDA.
- Data Processing Agreement (DPA) available on request
- Vulnerability Disclosure Program (VDP) active
- Strict Role-Based Access Control (RBAC)