Security & compliance
Your data is safe with us. We follow leading security and privacy standards, and independent auditors check our work every year.
Certifications and compliance
We hold the certifications enterprise AI teams ask for and follow the major privacy laws.
ISO 27001:2022
Our information security management system is certified to the international ISO 27001 standard and checked by an independent auditor every year.
SOC 2 Type II
An independent auditor tests our security, availability and confidentiality controls over a full review period, not just on one day.
GDPR
We handle personal data of people in the EU and UK in line with the GDPR, and sign a Data Processing Agreement with every client who needs one.
HIPAA
Health data is handled under HIPAA safeguards. We sign a Business Associate Agreement (BAA) for projects that involve protected health information.
CCPA
We respect the privacy rights of California residents, including the right to know, delete and opt out.
How we protect your data
Security is built into every project, from the first file we receive to the last one we delete.
Data protection
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Personal data removed or masked before work begins
- Only the data a project needs is collected
- Data deleted or returned at project end, with written confirmation
Access control
- Least-privilege, role-based access
- Single sign-on and multi-factor authentication
- Access reviewed regularly and removed promptly
- All access to client data is logged
People & workforce
- Background checks where the law allows
- Signed NDAs for every employee and contributor
- Security and privacy training when joining and every year
- Project-specific training for sensitive data
Secure delivery options
- Secure facilities with badge access and CCTV
- Clean-desk rules, no phones or personal devices
- Virtual desktops so data never leaves our systems
- Work inside your own cloud or tools if you prefer
Infrastructure & monitoring
- Hardened, managed laptops with disk encryption
- Continuous logging and security monitoring
- Regular vulnerability scans and patching
- Independent penetration tests every year
Incident response & continuity
- Written, tested incident response plan
- Clients told without undue delay if their data is affected
- Encrypted backups stored separately
- Business continuity and recovery plans tested every year
How we handle AI training data
AI data projects carry special risks, so we follow clear rules at every step.
Agree the rules
We sign an NDA and a DPA (and a BAA if needed), and agree where data may be stored and who may see it.
Protect on arrival
Data is moved over encrypted channels, and personal details are removed or masked before work starts.
Work with limits
Only trained, approved people work on your data, in secure tools or facilities, with every action logged.
Delete at the end
When the project ends, we return or delete your data and confirm it in writing.
Your data is yours
We never use your data to train our own models or for other clients. You own all the data and labels we deliver.
Ethical data collection
Every contributor gives informed consent, knows how their data will be used and is paid fairly for their work.
Security documents
Doing a security review? We can share our reports and agreements. Some documents need an NDA first.
Request documentsRead our privacy policy to see how we handle personal data.
- SOC 2 Type II reportAvailable under NDA
- ISO 27001 certificateAvailable on request
- Data Processing Agreement (DPA)Available on request
- Business Associate Agreement (BAA)For HIPAA projects
- Penetration test summaryAvailable under NDA
- Security questionnaires (SIG, CAIQ)Completed on request
Report a security issue
Found a vulnerability or think something is wrong? Please tell us through our contact form. We look at every report quickly and will keep you updated. Please give us time to fix the issue before sharing it publicly.
Have security questions?
Our team can walk you through our controls or join your security review.