Tolgee for Enterprise
The enterprise localization platform you can actually audit

ISO 27001
certified

GDPR
compliant
EU cloud
on Azure
Open
source
Why do enterprises choose Tolgee?
Enterprises choose Tolgee because it removes the two biggest risks of buying a localization platform: giving a third party access to your content, and being locked into a vendor you can’t leave. Tolgee is open source, so your security team can audit the exact code you deploy. You can run it in our EU cloud or entirely inside your own infrastructure. And your translations are always exportable in standard formats, so the exit door stays open.
Open source you can audit, not a black box
The Tolgee platform code is public on GitHub. The core is Apache-2.0, enterprise features are under the Tolgee EE license. Either way, your security team can review the code before deploying it. No NDA, no waiting for a vendor questionnaire response.
ISO 27001 certified
Our information security management system covers the development and operation of the platform. We share the certificate with prospects during evaluation.
Self-hosted or EU cloud. Your data, your rules.
Tolgee Cloud’s platform infrastructure runs in the European Union on Microsoft Azure, GDPR compliant with a DPA available. Or deploy Tolgee on your own servers, fully air-gapped. Your content never leaves your network.
Shipping Tolgee for more than 5 years
Tolgee has been built in the open since 2020. The code, the issue tracker, and the release history are all public, so you can see exactly how the platform evolves and how it’s maintained.
500k+
npm downloads per month
1.6M+
Docker Hub pulls
4,000+
GitHub stars
2020
building in the open since
$ docker compose up -d
Pulling tolgee/tolgee … done
Starting postgres … done
Tolgee never touches your source code
Every integration runs from your side: SDKs, CLI, REST API, file import and export. Tolgee never asks for access to your repositories, on any plan. Your code stays in your VCS, and only the translation content you choose to sync reaches the platform.
Built on technology your engineers already trust
A Spring Boot application written in Kotlin, backed by PostgreSQL, with Redis for caching and scale-out. Database changes run through Liquibase migrations. Boring, proven, and easy for your platform team to operate.
Security as a process, not a badge
We run responsible disclosure and publish security advisories, including CVEs, for the platform. When researchers find something, we fix it, credit them, and tell the world. You can read our full advisory history on GitHub instead of taking our word for it.
Our infrastructure is under continuous external vulnerability scanning, and all data is encrypted with AES-256 at rest and TLS 1.2+ in transit.
2023
publishing advisories since
12 h
critical first response
99.9%
contractual uptime SLA
Switching from another platform?
Moving from Lokalise, Phrase, or Crowdin is not a rewrite. Tolgee imports all major localization file formats, so you bring your existing translations, keys, and languages with you. Enterprise onboarding includes migration support from our team.
Procurement-ready
Security questionnaires, custom DPA and MSA, ISO certificate during evaluation, volume and multi-year agreements, invoicing by bank transfer. The documents your review needs are one email away. It won’t be your longest vendor onboarding.
Book a demo with our team, or start a self-hosted proof of concept today. Your security team is welcome to join the call.
Frequently asked questions
Is Tolgee ISO 27001 certified?
Yes. Tolgee is ISO 27001 certified. We share the certificate with prospects during evaluation.
Can Tolgee be self-hosted?
Yes. Tolgee is open source and can be deployed on your own infrastructure, including fully air-gapped environments. Free self-hosting covers up to 10 users; licensed tiers add SSO, granular permissions, and more.
Is Tolgee GDPR compliant?
Yes. Tolgee Cloud’s platform infrastructure runs in the European Union on Microsoft Azure, and we offer a Data Processing Agreement. Self-hosting gives you full control over data residency.
Does Tolgee need access to our source code?
No. All integrations run from your side. Tolgee never requires access to your repositories on any plan.
What technology does Tolgee run on?
The platform is built with Spring Boot and Kotlin on the JVM, with PostgreSQL as the database and Redis for caching and scale-out. It ships as Docker images for self-hosting.
Does Tolgee publish security advisories?
Yes. We run responsible disclosure and publish advisories, including CVEs, on GitHub.
How is our data encrypted?
All data is encrypted with AES-256 at rest and TLS 1.2+ in transit. This applies to the database, file storage, and all connections between services.
How does Tolgee test its security?
Continuous external vulnerability scanning of our infrastructure, responsible disclosure with published advisories, and a public codebase that anyone can review. ISO 27001 governs the whole process.
Do more languages mean more keys?
No. A key counts once, no matter how many languages you translate it into. No plan limits the number of languages, and importing your existing translations doesn’t cost anything.
Can we use the free self-hosted version commercially?
Yes. The free Community edition can run in production for organizations with up to 10 users, on your own infrastructure. A paid license adds SSO, granular permissions, and the rest of the enterprise feature set.
Will you complete our security or supplier questionnaire?
Yes. Completing security questionnaires, vendor assessments, and supplier due-diligence paperwork is part of the Enterprise plan.
Can we run a proof of concept first?
Yes. Start with the 14-day cloud trial or the free self-hosted Community edition; longer evaluation setups are available for enterprise POCs. Staging and non-production instances typically don’t need a license at all.
Can we migrate from Lokalise, Phrase, or Crowdin?
Yes. Tolgee imports all major localization file formats, so your translations, keys, and languages come with you. Enterprise onboarding includes migration support.


