A security questionnaire you cannot answer
A new client, a law firm, sends a security questionnaire before approving your agency. Where are our documents stored? Who can access them? Are they ever held on personal devices? How do you ensure deletion after the job? Your honest answer is that files are emailed to freelancers, who work on them on their own laptops, in their own CAT tools, and you ask them to delete files afterwards. You have signed NDAs. You do not have much else.
The client is polite but clear: that is not good enough for their content.
Why files end up everywhere
- Freelancers work on their own devices, which is the nature of freelancing.
- Desktop CAT tools need files downloaded to the device.
- Files are sent by email or transfer links, and copies stay in inboxes and download folders.
- Deletion after a job depends on each translator remembering.
- Nothing records who has accessed what.
None of this implies freelancers are careless. Most are careful. The problem is that you cannot show it.
What it costs
Lost clients in legal, financial, medical and corporate sectors, where security questionnaires are routine. Exposure if a freelancer's device is lost or compromised, which your own data protection obligations may make serious. Time spent answering questionnaires with caveats. And a limit on the kind of work you can win.
| Question clients ask | Typical answer | Answer with the build |
|---|---|---|
| Where are files stored? | Various places | In your agreed cloud region |
| Are they on personal devices? | Sometimes | Not for sensitive jobs; access through the browser |
| Who accessed them? | We believe only the translator | Access log per job |
| When is access removed? | We ask translators to delete | Automatically when the job closes |
| How are they deleted? | On request | Under a retention rule you set, recorded |
How we build confidential job handling
- Clients or jobs can be marked as confidential, which changes how the job is handled from the start.
- Confidential jobs are set up in a server or cloud CAT tool, such as Phrase, XTM, memoQ server with its web editor or Trados Cloud, where translators work in the browser rather than on downloaded files.
- Access is granted to the named translator and reviser for that job only, with sign-in through the platform, and ends automatically when the job closes.
- Downloads of source and target files are disabled for confidential jobs where the platform allows, or logged where it does not.
- Files are not sent by email. Clients upload through your portal, and deliveries are downloaded from it.
- Access and download logs are kept per job, and retention rules delete files after the period agreed with the client, with a deletion record.
- Your NDAs and freelancer agreements are recorded against each vendor, and confidential jobs are only offered to vendors with the right agreements in place.
Some translators prefer their desktop tools, and for non-confidential work that can continue. The browser route is used where the client's content requires it.
What changes
You can answer a security questionnaire with a clear description and records, rather than caveats. Sensitive files stay in a controlled environment. Access is limited and ends by itself. Clients in regulated sectors become winnable. And freelancers benefit too: they do not have to worry about holding a client's confidential files on their own machines.
Security is never absolute, and no setup removes every risk. What it gives you is control and evidence, which is what careful clients are really asking for.
Could this be holding you back?
- Confidential files are emailed to freelancers.
- You rely on translators to delete files after jobs.
- Security questionnaires are hard to answer honestly.
- You have lost or avoided clients over data security.
- You cannot say who has accessed a given client's files.