New: conversational Urdu and Punjabi speech corpora now licensable  See the catalog →

Security

Built to survive your security review

We have been through enough enterprise vendor assessments to have the answers ready. Ask for the pack and you will get it the same day.

Controls

What is actually in place

Stated plainly, including where we are still in progress.

  • ISO 27001-aligned ISMS with documented controls, risk register and annual review
  • SOC 2 Type II readiness in progress; current status stated honestly on request
  • Encryption in transit (TLS 1.3) and at rest (AES-256), customer-managed keys available
  • SSO / SAML, role-based access control, least privilege, and per-asset access logging
  • Annual third-party penetration testing; summary report shared under NDA
  • Secure annotation facilities: no personal devices, no removable media, no internet on the floor
  • On-prem and in-your-VPC deployment options for regulated data
  • Background-checked staff, signed confidentiality agreements, offboarding revocation within 24 hours
  • Documented incident response plan with named notification timelines

Delivery

Three ways data reaches you

Your bucket

Direct to your S3, GCS or Azure destination with per-batch SHA-256 checksums and signed manifests. The default, and the fastest.

Time-limited signed URLs

Where you would rather not grant write access, we host and issue expiring links per batch, with download logging.

In your VPC or on-prem

For regulated data, our annotators work inside your environment on your tooling. Nothing leaves your perimeter.

Before anything leaves our environment a PII detection and redaction pass runs across every record: faces, licence plates, CNIC numbers, screen content, address signage and spoken identifiers. Anything flagged is redacted or removed per your written instruction.

Answers

Security questions

We operate ISO 27001-aligned controls and are in active SOC 2 Type II readiness — we say “aligned” and “in progress” deliberately rather than implying certificates we do not yet hold. A completed CAIQ, our penetration-test summary, insurance certificates and security architecture documentation are available under NDA on request.

Yes. We support delivery to your S3, GCS or Azure bucket, work-in-your-VPC arrangements, on-prem annotation for regulated clients, and secure-facility work where no annotator has internet access or personal devices on the floor.

Usually within three business days, often faster. We keep a completed CAIQ and a standard control matrix current specifically so that vendor review does not become the critical path on your project.

We run a documented incident response plan with named notification timelines written into the MSA. You are told what happened, which of your data was affected, and what we are doing about it — before we have a complete picture, not after.

Send us your security questionnaire.

We will complete it and return it, usually within three business days.

Average first response: under 6 business hours. NDAs signed same day.

Free samples Get a quote