Data Security

Data Security

Ensuring the confidentiality, integrity and availability of our clients' data is at the heart of our work at Annotation Support. Security in our annotation and data-labeling processes is underpinned at every step of the way, ranging from ingestion to processing to deletion.

Data Security and Protection

Our Approach to Security

We are aware that data that you share with us for annotation may be sensitive, proprietary or regulated. We deploy defence in depth security techniques to ensure that your data remains secure, whether it is being moved, stored or labeled by our staff.

Data Encryption

In Transit: All data transferred to and from our platform is encrypted.

At rest: Client data is securely encrypted at rest with stronger encryption standards.

Key management: Encryption keys are managed through with strict rotation and access policies.

DATA SECURITY

Security Built Into Every Step

We follow structured security practices to protect client data throughout the annotation lifecycle — from access and infrastructure to retention and deletion.

01

Access Controls

Access to client information is controlled, monitored and limited according to role and need.

  • Role-based access control (RBAC) :Only annotators and/or staff as needed to accomplish a task have access to the client's data.
  • Least privilege principle : Accesses and capabilities are limited to access what is just needed for any team member's role.
  • Multi-factor authentication (MFA) :Implemented for all internal systems handling client data.
  • Audit logging and access monitoring :Access to Data and other sensitive information is Audit-logged and monitored.
02

Annotator Vetting & Training

Personnel handling client datasets are verified, trained and bound by confidentiality requirements.

  • All annotators are background checked and verified before hiring.
  • Confidentiality and data protection agreements (NDAs) are signed by all the annotators prior to accessing any client data.
  • Regular security awareness training is provided for all staff responsible for any client datasets.
  • Regular security awareness training
03

Data Isolation & Segregation

Client datasets are separated to help prevent unauthorized access between different projects.

  • Client data is logically and, if necessary, physically separated, ensuring it is not accessible by other clients.
  • For clients who have more isolation needs, there are designated environments or workspaces.
04

Data Retention & Deletion

Client data is retained only for the period required to complete the project or as agreed in the DPA.

  • Client data is retained only for the duration necessary to complete the annotation project, or as otherwise agreed in a Data Processing Agreement (DPA).
  • Once the project has been finished or requested by the client, data is securely deleted, and this deletion is verified in written form.
05

Infrastructure Security

Production infrastructure uses network security, monitoring and controlled access mechanisms.

  • Hosted on network security infrastructure, using standard industry hardware and network security standards.
  • Periodic scans and penetration tests.
  • Production systems are isolated from unauthorized access utilizing network segmentation and firewalls.
  • Anomalous activity detection and automatic alerting through infrastructure monitoring is available round-the-clock.
06

Compliance

We adopt practices aligned with accepted data protection frameworks and regulations.

✓
GDPR General Data Protection Regulation
✓
CCPA California Consumer Privacy Act
SECURITY & DATA PROTECTION

Ready When It Matters.

Structured response procedures and flexible data protection options help us address security incidents and specialized client requirements.

SECURE RESPONSE
01 Detect
02 Contain
03 Investigate
04 Notify
INCIDENT RESPONSE

A documented process for handling incidents.

We maintain an incident response plan with documented procedures for detection, containment, investigation and notification.

01
Detection

Identify potential security threats and unauthorized access early.

02
Containment

Isolate incidents quickly to prevent further data exposure.

03
Investigation

Analyze the incident to determine its cause, scope, and impact.

04
Notification

Promptly inform the relevant stakeholders about confirmed security incidents.

If an incident involving disclosure of client data is reported or discovered, the relevant client will be made aware within [TIMEFRAME e.g., 72 hours], subject to applicable laws and contractual obligations.

DATA SECURITY & COMPLIANCE

Data Processing Agreements

Protecting sensitive data is at the core of how we work. We provide flexible data processing agreements and security arrangements tailored to the requirements of your project.

Flexible agreements for sensitive projects

We provide Data Processing Agreements (DPAs) and are able to support special security needs, such as on-premises annotation requirements or custom ordering of an NDA, for certain projects that are sensitive.

01

Data Processing Agreements

02

On-Premises Requirements

03

Custom NDA Support

SECURITY & COMPLIANCE

Questions About Our Security Practices?

Please email business@annotationsupport.com if you have any specific security or compliance questions, would like a copy of our security documentation, or have any questions or interest in our requirements of any sensitive dataset.

Contact Our Team
close
close

© 2019 - 2026 Annotation Support. All Rights Reserved. Designed by Dreamdezigns