Access Controls
Access to client information is controlled, monitored and limited according to role and need.
- Role-based access control (RBAC) :Only annotators and/or staff as needed to accomplish a task have access to the client's data.
- Least privilege principle : Accesses and capabilities are limited to access what is just needed for any team member's role.
- Multi-factor authentication (MFA) :Implemented for all internal systems handling client data.
- Audit logging and access monitoring :Access to Data and other sensitive information is Audit-logged and monitored.
