Security & data handling

How your data is handled

The contractual, technical and personnel controls that apply to client data, described as they actually operate — including the parts where the honest answer is "ask us and we will tell you".

Security pages are usually written to reassure. This one is written so that your security reviewer can find out what is true without a call.

The risk in annotation work is people, not infrastructure

Annotation is unusual among data services in that humans necessarily read the data. Encryption at rest is straightforward; the harder question is who is in a position to read a record, on what device, under what agreement, and for how long after the project ends.

So the controls that matter most here are the ones governing access and personnel — who is staffed on a project, what they can reach, what happens on their screen, and what obligations survive their leaving it. Infrastructure controls are necessary and are described below, but they are not where this kind of work goes wrong.

Everything on this page is agreed per engagement and written into the contract. Where a requirement of yours is stricter than our default, it becomes a contractual term rather than an assurance.

At a glance

Contractual
NDA before any data is shared. A data processing agreement where personal information is involved.
Access
Role-based, least privilege, multi-factor authentication, limited to the people staffed on the project.
Environment
Isolated working environment per engagement; encrypted in transit and at rest.
Lifecycle
Retention period and deletion method agreed in the contract, with confirmation on completion.
Certifications
We do not claim certifications we do not hold. Ask, and you will get a direct answer.

Controls

What is in place

Six areas, each configurable upward for engagements that require it.

Contractual controls

Nothing is shared before an NDA is signed, and personal information is handled under a data processing agreement that names the purpose, the scope and the retention period.

  • Mutual NDA before data transfer
  • Data processing agreement where applicable
  • Named purpose and retention terms
  • Subcontracting disclosed, not assumed

Access control

Access is granted per project to the people staffed on it, at the minimum level the role requires, and revoked when the assignment ends rather than when someone remembers.

  • Role-based access, least privilege
  • Multi-factor authentication enforced
  • Access reviewed on staffing change
  • Access logs retained and auditable

Working environment

Each engagement runs in an isolated environment, and we can work inside your platform instead if your policy requires the data never to leave it.

  • Per-engagement isolation
  • Encrypted in transit and at rest
  • Work inside client-provided tooling on request
  • Download and export restrictions where required

Personnel controls

Annotators are bound by individual confidentiality agreements, briefed on the handling rules for the specific project, and their obligations continue after the project ends.

  • Individual confidentiality agreements
  • Per-project handling briefing
  • Obligations survive project end
  • Staffing list available to the client

Data lifecycle

Data is retained only for the agreed period and deleted by the agreed method, with written confirmation once deletion is complete.

  • Agreed retention period
  • Defined deletion method
  • Written deletion confirmation
  • No retention for internal reuse

Incident handling

A defined internal escalation path, prompt notification to you, and a written account of what happened rather than a reassurance that it has been dealt with.

  • Defined escalation path
  • Prompt client notification
  • Written incident account
  • Corrective actions recorded

Lifecycle

What happens to your data, in order

Each step is a contractual term, not a policy statement.

  1. 01

    Before transfer

    NDA signed, and where personal information is in scope, a data processing agreement naming purpose, scope and retention. Transfer method agreed in writing.

  2. 02

    On receipt

    Data lands in the environment agreed for the engagement. Access is provisioned for the project team only, at the level each role requires.

  3. 03

    During the project

    Work happens inside that environment. Access changes as staffing changes, and access logs are retained for the duration.

  4. 04

    On delivery

    Deliverables are transferred by the agreed method. Working copies are consolidated so that what remains is known rather than assumed.

  5. 05

    After completion

    Data is deleted at the end of the agreed retention period by the agreed method, and we confirm the deletion in writing.

Plain statement

What we do not claim

This section exists because the absence of a claim is easy to miss on a security page.

We do not hold or claim any certification, audit report or attestation that is not stated explicitly in our contract with you. If a certification scheme matters to your procurement process, ask us directly and you will get a direct answer about whether we hold it — including when the answer is no.

We do not publish uptime figures, breach statistics or accuracy guarantees, because we have not had them independently verified and an unverified number on a security page is worse than no number at all.

We do not retain client data for internal reuse, model training or portfolio purposes. Sample material shown on this website is our own, created for illustration.

If a real certification is ever obtained, it will be added here deliberately, with its scope and its date. It will not arrive as filler.

Procurement

For your security review

The things worth asking us, and what we can provide without a lengthy process.

  • A completed security questionnaire in your own format, rather than a link to this page.
  • The specific controls that would apply to your engagement, written into the contract as terms.
  • Confirmation of where data would be stored and processed, and by whom.
  • The staffing list for your project, and the confidentiality agreements that bind it.
  • Our answer on any certification scheme you require — including a plain no where that is the answer.
  • Retention and deletion terms, and the form the deletion confirmation takes.

FAQ

About security and data handling

The questions a security reviewer asks first.

We do not claim any certification that is not written into our contract with you. Ask us directly about a specific scheme and you will get a direct answer rather than a deflection. We would rather lose a procurement process for telling the truth than win one and be found out during an audit.

No. Access is granted per project, at the minimum level the role requires, to the people staffed on it. Where a dataset contains material that only part of the team needs, access is partitioned accordingly. The staffing list for your project is available to you on request.

Yes. We regularly work inside client-provided annotation platforms and virtual desktops where policy requires that the data never leave your infrastructure. It changes the tooling, not the guideline or the review process, and we will tell you where a restriction genuinely limits what the QA process can do.

Where a project involves personal information we operate as a processor under a data processing agreement that names the purpose, the scope and the retention period, and we follow the handling instructions in that agreement rather than a general policy. Japan’s Act on the Protection of Personal Information, and where relevant the GDPR, shape those terms. We are not in a position to give you legal advice on your own obligations, and we will say so rather than improvise.

It is deleted at the end of the retention period agreed in the contract, by the agreed method, and we confirm the deletion to you in writing. We do not keep client data for internal reuse, for model training or as portfolio material. If you need a shorter retention period than our default, that becomes a contractual term.

Security

Send us your questionnaire.

We would rather answer your security review in your format, before a pilot, than describe our posture in general terms on a web page.

NDA before you share any data. Pilot scoping is free.