Salam.AI

Security & trust

Your words.
Handled with care.

Understand where audio is processed, what is saved, and what you choose to share. Privacy controls should be as clear as the conversation.

Understand the data path

Different features. Clear boundaries.

01

Provider-direct voice translation

The main voice engines send audio from your browser directly to the provider. Salam.AI handles authentication, session credentials, limits and usage accounting.

02

Audio paths depend on the mode

Subtitle-only translation and optional language detection send audio through Salam.AI services. Remote speakers and participant phones use scoped relays; audience listening uses a distribution service.

03

Saved content is encrypted before upload

Optional audio recordings, History transcripts and saved SRT/Markdown files are encrypted in the browser. Authorised playback and file downloads decrypt on the client.

04

Shared text is readable by the sharing service

Live caption feeds, overlays, audience captions and published summaries are separate from encrypted archives. Enable only the tracks and summaries you want to disclose; use admission, expiry and revocation controls.

05

Summaries process text on request

Requesting a summary sends the transcript for server-side model processing. Publishing that result to an audience stores a readable shared copy under the channel’s access and lifetime controls.

The public website demo

Thirty seconds to try it.
A clear view of your data.

The homepage demo securely relays microphone audio to our translation service providers and returns translated speech and text. This relay is separate from the main console’s provider-direct voice paths.

The demo does not save audio or transcripts on our servers or in browser storage. Text remains on the page until you clear it or leave. Our infrastructure and translation service providers process the connection under their applicable service policies; those providers may retain operational data.

A signed, one-day browser cookie, daily pseudonymous network identifiers and short-lived session records help enforce the free-demo limits. Quota records are removed after two days of inactivity. The demo does not log spoken content. Starting a demo requires acknowledgement of this processing and browser microphone permission.

The session ends after 30 seconds or when you stop or leave the page. Use headphones to reduce feedback. Live AI transcripts and translations may contain errors.

A clear welcome includes clear terms

Your organisation. Your notices.

01

Publish the right operator information

Tenant administrators can edit operator and contact details and English/Malay privacy and terms notices. Preview drafts before publishing; the default operator is Ordinexis Sdn Bhd. These notices are separate from the 37 public interface languages.

02

Acceptance follows the notice version

Privacy and terms acceptance is required at the main console, campaign, audience, participant and remote-speaker entry points. A newly published version prompts acceptance again on the next entry.

03

Familiar on a return visit

Account acceptance can be remembered. Anonymous acceptance is remembered in the same browser while its storage remains available; another device or cleared storage may require it again. Notices remain available to read through help or page links.

Controls that matter

Privacy with practical control.

01

Team data stays separated

Tenant-scoped queries run under a restricted database role, adding a database boundary to application-level access controls.

02

Sign in with the right safeguards

TOTP and backup codes support account protection. Where enabled, Magic Login email links and QR codes are short-lived and single-use, with normal access checks. Password recovery is available across account roles. Teams remain invite-only.

03

Per-language audience permissions

Set audio, original and translated captions, approval, summary sharing and expiry separately for each audience channel. An organisation can enforce text-only phone sharing.

04

A tamper-evident audit trail

Security and administrative events form a verifiable chain. Audit records support review without storing spoken content in event metadata.

05

Scoped credentials and revocation

Provider keys stay on server-side services. Browsers receive scoped session credentials. Participant pairings, remote-speaker access and campaign delegates each have their own access boundary.

Let everyone be part of it

Your next conversation.
A little more connected.

Open Salam.AI console

Already part of a team? Sign in to start a session.

Explore plans for your organisation →