Security and quality
The operation needs your trust.
Standards matter. So does what happens when the operation is tested. Here is how we protect the systems around your work, what has been independently assessed and what your team can review.
Standards are the baseline.
ISO 9001:2015
Quality management for our translation production and supporting business processes.
ISO 17100:2015
Translation-service processes, resource competence and qualifications.
Both are audited annually. They cover how we manage quality and translation work. Security controls are assessed separately.
Independent assessment
The client portal. Tested, fixed, retested.
Securitum independently penetration-tested Kobalt’s multi-tenant client portal in July 2026. The test found no critical or high-severity vulnerabilities. One medium-severity issue was found and fixed.
The testers also tried to reach one client’s data from another client’s account. Isolation held in both directions.
Securitum retested the portal in August and confirmed that all significant vulnerabilities had been fixed.
Findings become engineering work, not paperwork.
The assessment covered the portal using magic-link authentication. Single sign-on was added later and was not part of that assessment.
Securitum’s letter of attestation is available on request.
Security lives in the operation.
Access follows the user.
Clients can sign in with single-use email links. Single sign-on through a client’s own identity provider is also supported and has been verified with Okta. With single sign-on, removing someone in the identity provider ends their portal access within minutes.
Actions leave a record.
The portal records sign-ins, views, approvals, uploads, downloads and refused attempts. Records are kept for 12 months in the EU. Document content is never written to the audit log.
The portal does not keep your files.
Everything moving to and from the portal is encrypted. Uploads pass straight through to our project system, and the systems that store your files encrypt them at rest.
We keep testing it.
Authenticated security scans run every quarter against a production-equivalent portal. Vulnerabilities are fixed on deadlines set by severity. Critical issues are contained within 24 hours. The findings from the July penetration test were fixed within nine days of the report.
Account requirements shape access.
The systems that store your files are hosted in the EU. If your organisation restricts where its content can be worked on, we can restrict the countries your linguists work from for that account.
Security also means being able to recover.
We have written incident response and business continuity plans. Our incident plan sets a four-hour triage target for reported incidents.
We test recovery as well as prevention. In our May 2026 recovery test, the client portal was back online in under five minutes against a one-hour target.
Kobalt works fully remotely, so the operation does not depend on a single office staying available.
Bring your security questions.
For your security review we can share our portal architecture, data residency statement, subprocessor list, encryption and access-control documentation, incident response and business continuity plans, vulnerability management policy, security training programme, an audit-log sample and Securitum’s letter of attestation.
Some documents require an NDA. Tell us what your team needs to assess and we will work through it with you.