Security
Confidentiality is the product, not a feature.
Labs hand us prompts, model outputs, and proprietary domain material. Everything below exists so that material never leaves the boundary you agreed to.
Certification status
INRAXO runs on tier 1 cloud infrastructure whose providers hold SOC 2 Type II and ISO 27001 certifications. INRAXO's own organizational certifications are on the roadmap, and our internal controls are built to those standards.
We do not claim certifications we do not hold. If a certification matters for your vendor process, ask us and we will tell you exactly where we stand.
01 / Infrastructure
- —Encryption in transit and at rest
- —Role based access control with least privilege
- —Audit logs across systems and task platforms
- —Endpoint security on every machine used for client work
02 / Privacy and legal
- —Client NDA signed before any work begins
- —Data Processing Agreements
- —GDPR ready practices
- —PII handling and data masking
- —Data retention and deletion policies
- —Contributor NDAs on every project
- —Confidentiality by default | contributors never know who the end client is
- —Data minimisation | contributors only see their assigned task, never the full dataset
03 / Workforce
- —Background verification
- —Confidentiality training
- —Trained and tested annotators
- —Secure workstations
- —QA process on every deliverable
- —Per contributor accountability
How an engagement is governed
NDA before any details
Every client engagement starts with a signed NDA. No project details, prompts or sample material are discussed before it is in place. A Data Processing Agreement follows, covering handling, retention and deletion.
Contributor level NDAs and data minimisation
Every contributor signs a project level NDA before receiving any task. Data is minimised so a contributor only ever sees their specific assigned task | never the full dataset, and never the client's identity.
Retention and deletion
Client data is retained only for the duration of the project plus 30 days, to cover revisions and disputes. After that it is deleted from our working systems. Deletion happens immediately on written request, or at contract end by default. We confirm deletion in writing.
Breach notification
If a data incident affecting client material occurs, we notify affected clients within 72 hours of becoming aware of it, with what we know and what we are doing about it.
Subprocessors and vendors
A current list of subprocessors and infrastructure vendors is available on request as part of any vendor assessment.
Need our security documentation for a vendor assessment?
Email info@inraxo.com.