The IT brief

Localization infrastructure your security team can approve.

Localization Studio runs entirely inside your environment: your servers, your storage, your models, your rules. Here is how it is put together, and exactly where every control stands today.

Architecture

One process. Your data path, end to end.

Clients talk to a single application. The application talks to your database, your file storage, and the model provider you configure. Nothing routes through Patois Labs.

Localization Studio deployment architecture Clients (web UI, CLI, and API or MCP agents) connect to Localization Studio, one process built as a modular monolith. Inside it: translation memory and glossaries, LLMemory retrieval, workflows with LQA, the CAT editor, the prompt tap, and connectors, on top of named ports for identity, models, storage, scheduling, and telemetry. The application talks to your data store (SQLite by default, PostgreSQL supported), your file storage, and your identity provider over SAML 2.0 and SCIM 2.0, proven against Okta. Model traffic goes only where you configure it: fully offline local models, your internal endpoints, approved frontier APIs, or a hybrid chosen per workflow. No Patois service is in the data path. Web UI your team, in a browser CLI headless and CI API · MCP agents everything, scriptable Localization Studio one process · a modular monolith TM · glossaries LLMemory (RAG) Workflows · LQA CAT editor Prompt tap Connectors NAMED PORTS Identity · Models · Storage · Scheduler · Telemetry Your data store SQLite by default PostgreSQL supported Your file storage uploads · assets · keyfiles Your identity provider SAML 2.0 · SCIM 2.0 proven against Okta Model traffic goes only where you configure it A · Fully offline local GPU · LM Studio-style B · Internal endpoints your own model servers C · Approved frontier APIs your keys, your terms D · Hybrid chosen per workflow

Model traffic follows the customer's configuration. There is no Patois-side service in the data path.

Controls

The controls.

Deployment

Single node. No orchestration required.

Runtime
One FastAPI process, shipped as a Docker image or run as plain Python. There is no Kubernetes to stand up and no service mesh to babysit.
Topology
One node is the whole story: a laptop, a VM, or an air-gapped box that has never seen the internet. A reference cloud deployment exists for teams that want a hosted starting point.
Data store
SQLite by default, which means zero database operations on day one. PostgreSQL is supported when your platform team wants it.
Hardware
Modest. A GPU matters only if you host models locally; pointed at an API, it runs on almost anything.

Identity and access

SSO and provisioning, proven against a real IdP.

SSO
SAML 2.0 single sign-on, interop-tested against a real Okta organization. A live round trip, not a checkbox on a datasheet.
Provisioning
SCIM 2.0 user lifecycle: users and groups created, updated, and deprovisioned, exercised against that same Okta org.
Authorization
Role-based access control separates who can read, translate, review, and administer.
Headless
API keys for automation, CI, and the CLI, governed by the same permission model as the people.
Rollout
Enterprise features ship flag-gated and off by default. Nothing turns on until you turn it on.

Audit and data protection

Every action recorded, everything at rest encrypted.

Audit
Every action lands in an append-only, tamper-evident audit chain, and the chain itself is monitored. If history gets touched, it shows.
Encryption
Data and key material are encrypted at rest.
Transport
Hardened response headers and cookie flags, with HSTS verified on the live deployment.
Data rights
GDPR-grade erasure and export are built into the data model, not bolted on afterward.
Recovery
Full-install backup with a documented restore path. Disaster recovery you can rehearse, not just cite.

Supply chain and updates

You review and deploy on your own schedule.

Scanning
Every dependency is vulnerability-scanned in CI (pip-audit) against a managed advisory baseline, so a new advisory surfaces loudly instead of shipping quietly.
Delivery
Updates arrive as source through your private repository channel. You can read every diff before it goes anywhere near production.
Control
You review, you schedule, you deploy. Nothing in your environment ever auto-updates.

Telemetry

None.

The software phones home to no one.

No analytics, no usage beacons, and no license callbacks reach Patois Labs. What runs in your environment stays in your environment.

Compliance posture

SOC 2 and ISO 27001: not yet certified.

Formal gap assessments are complete against both standards, the controls are documented, and the remediation roadmap is active. Ask, and I will walk you through exactly where we stand.

SOC 2 · gap assessment complete ISO 27001 · gap assessment complete Remediation roadmap · active

Continuity

If Patois Labs disappears, you keep running.

Delivery is the source itself, which makes escrow built in. You hold the code, your license, and a system already running inside your environment. There is no vendor lock to unwind and no server to lose access to. The software keeps working whether or not Patois Labs does.

Bring your architect.

Book a technical walkthrough and put the whole system in front of the person whose signature you need.

Schedule a technical walkthrough →

or email brent@patoislabs.com