The IT brief
Localization infrastructure your security team can approve.
Localization Studio runs entirely inside your environment: your servers, your storage, your models, your rules. Here is how it is put together, and exactly where every control stands today.
Architecture
One process. Your data path, end to end.
Clients talk to a single application. The application talks to your database, your file storage, and the model provider you configure. Nothing routes through Patois Labs.
Model traffic follows the customer's configuration. There is no Patois-side service in the data path.
Controls
The controls.
Deployment
Single node. No orchestration required.
- Runtime
- One FastAPI process, shipped as a Docker image or run as plain Python. There is no Kubernetes to stand up and no service mesh to babysit.
- Topology
- One node is the whole story: a laptop, a VM, or an air-gapped box that has never seen the internet. A reference cloud deployment exists for teams that want a hosted starting point.
- Data store
- SQLite by default, which means zero database operations on day one. PostgreSQL is supported when your platform team wants it.
- Hardware
- Modest. A GPU matters only if you host models locally; pointed at an API, it runs on almost anything.
Identity and access
SSO and provisioning, proven against a real IdP.
- SSO
- SAML 2.0 single sign-on, interop-tested against a real Okta organization. A live round trip, not a checkbox on a datasheet.
- Provisioning
- SCIM 2.0 user lifecycle: users and groups created, updated, and deprovisioned, exercised against that same Okta org.
- Authorization
- Role-based access control separates who can read, translate, review, and administer.
- Headless
- API keys for automation, CI, and the CLI, governed by the same permission model as the people.
- Rollout
- Enterprise features ship flag-gated and off by default. Nothing turns on until you turn it on.
Audit and data protection
Every action recorded, everything at rest encrypted.
- Audit
- Every action lands in an append-only, tamper-evident audit chain, and the chain itself is monitored. If history gets touched, it shows.
- Encryption
- Data and key material are encrypted at rest.
- Transport
- Hardened response headers and cookie flags, with HSTS verified on the live deployment.
- Data rights
- GDPR-grade erasure and export are built into the data model, not bolted on afterward.
- Recovery
- Full-install backup with a documented restore path. Disaster recovery you can rehearse, not just cite.
Supply chain and updates
You review and deploy on your own schedule.
- Scanning
- Every dependency is vulnerability-scanned in CI (pip-audit) against a managed advisory baseline, so a new advisory surfaces loudly instead of shipping quietly.
- Delivery
- Updates arrive as source through your private repository channel. You can read every diff before it goes anywhere near production.
- Control
- You review, you schedule, you deploy. Nothing in your environment ever auto-updates.
Telemetry
None.
The software phones home to no one.
No analytics, no usage beacons, and no license callbacks reach Patois Labs. What runs in your environment stays in your environment.
Compliance posture
SOC 2 and ISO 27001: not yet certified.
Formal gap assessments are complete against both standards, the controls are documented, and the remediation roadmap is active. Ask, and I will walk you through exactly where we stand.
SOC 2 · gap assessment complete ISO 27001 · gap assessment complete Remediation roadmap · active
Continuity
If Patois Labs disappears, you keep running.
Delivery is the source itself, which makes escrow built in. You hold the code, your license, and a system already running inside your environment. There is no vendor lock to unwind and no server to lose access to. The software keeps working whether or not Patois Labs does.
Bring your architect.
Book a technical walkthrough and put the whole system in front of the person whose signature you need.
Schedule a technical walkthrough →
or email brent@patoislabs.com