Skip to main content

wxrks AI Policy

wxrks's governance principles for AI-powered features: how AI is used, what happens to your data, and the security and compliance standards behind it.

Introduction

wxrks builds AI into the platform to make translation and localization faster, not to replace the humans doing the work or to put your content at risk. This policy explains wxrks's overall approach to AI: what it's used for, the principles behind how it's built, how your data is handled when AI is involved, and the security and compliance standards that apply.

💡 Who is this for? This guide is for Account Admins and anyone evaluating wxrks's AI governance and data practices who need to understand how wxrks develops, secures, and governs its AI-powered features.


How wxrks uses AI

AI shows up in wxrks in a few specific places: Augmented Actions in the Editor (translation suggestions, alternative wording, proofreading, tag fixes, and quality checks like Smells and Sous-Chef), and Machine Translation providers connected to a project. Every one of these grounds its output in content wxrks already has about your account — your Translation Memories, Glossaries, and MT output — rather than generating translations blind.

None of this happens automatically to your content. Augmented Actions is off by default and must be turned on by an Account Admin, and every action it produces is a suggestion — a linguist or reviewer still decides whether to accept it. For the full walkthrough of turning Augmented Actions on and using it in the Editor, see wxrks Augmented Actions. For connecting a Machine Translation engine to a project, see Connect a Machine Translation (MT) Provider to wxrks.


AI development principles

  • Works out of the box, with no vendor lock-in. Augmented Actions runs on wxrks's own built-in AI with no setup required. An Account Admin can instead connect a custom OpenAI, Azure OpenAI, or Google Gemini account, so an organization can use the provider that fits its own procurement, compliance, or data-residency requirements instead of being tied to one vendor. See Configure Custom AI Providers with Model Management for the setup steps.

  • Context-grounded, not free-form generation. AI suggestions are built from your own Translation Memories, Glossaries, and Machine Translation output, so results reflect your terminology and prior translations instead of a generic model guess.

  • Stateless models. The AI models wxrks integrates with are stateless by design — each request is processed on its own, with no memory of previous interactions carried forward.

  • Human-in-the-loop by default. AI accelerates the translation process; it doesn't run unsupervised. Every Augmented Action produces a suggestion that a linguist or reviewer chooses to apply, edit, or discard.


Data handling and ownership

  • Your data stays yours. Customer content and project data are not used to train external AI models, and are not shared with third parties beyond what's needed to process a specific AI request you've opted into.

  • Data residency. wxrks stores customer data on AWS infrastructure, with a primary cluster in the US (AWS us-east-1) and a secondary cluster in the EU (AWS eu-west-1).

  • Aggregate metrics only, never content. wxrks may use anonymized, aggregated usage metrics (for example, overall project volumes) to improve platform performance — never the actual text of your projects.

  • What happens when you enable a GPT-based provider. Turning on Augmented Actions with OpenAI or Azure OpenAI as the provider means specific segment content is sent to that provider's API to generate a suggestion. Exactly what happens to that data once it leaves wxrks — retention windows, each provider's own privacy terms, and how it's transmitted — is covered in detail in wxrks AI Privacy: Data Shared with AI Providers.


Privacy and security practices

  • SOC 2 Type II certified. wxrks is audited by an independent third party on a recurring basis to verify its data protection and operational controls.

  • Encryption. Data is encrypted in transit using TLS, and sensitive credentials and keys are encrypted at rest via AWS Key Management Service (KMS).

  • Role-based access. Access to account data is controlled through roles and permissions, so only the people you've granted access can see a given piece of data; wxrks also supports multi-factor authentication on user accounts.

  • Auditability. If you need a record of activity on your account, your Customer Success Manager can provide a full event log on request.

For the complete technical and legal detail behind these practices, see wxrks.com/security, the Privacy Policy, the Data Processing Agreement, and the Acceptable Use Policy.


Responsible AI governance

AI-powered features are opt-in, not opt-out: Augmented Actions stays off across an entire account until an Account Admin turns it on, and it can be scoped down further at the Organizational Unit and individual user level. Nothing is sent to any AI provider until that decision is made. See wxrks Augmented Actions for exactly how those controls work.

Once enabled, every AI suggestion remains reviewable and reversible — nothing is published to a translation without a linguist or reviewer accepting it, and wxrks's own governance controls (roles, permissions, audit logs) apply to AI-assisted work the same way they apply to everything else on the platform.


Related articles


Questions about this policy

For compliance documentation or any question about this policy, contact [email protected].

Did this answer your question?