Least-privilege access
Reviewers should see only the projects, items, and fields required to do the work.
Security for expert AI data programs is mostly access design: who can see which items, in which tool, for how long. This page describes operating principles. It does not claim SOC 2, HIPAA, ISO, GDPR certification, or any other audit badge.
We are not a freelancer marketplace or traditional staffing company.
Security is mostly access design: who can see which items, in which tool, for how long. Programs can use least-privilege, project-scoped access, confidentiality terms, data minimization, and revocation when work ends. This page does not claim SOC 2, HIPAA, ISO, or GDPR certification.
Reviewers should see only the projects, items, and fields required to do the work.
When the safer design is to keep data in the client environment, experts work there. Labels do not need to travel to be useful.
Access is granted for a named engagement, not as a standing right to a general data lake.
Experts are contracted with confidentiality obligations appropriate to the project.
If a reviewer does not need a patient identifier, a customer name, or a live deal, that field should not be in the item.
When the project ends, access is intended to be revoked rather than left idle.
Downloads, screenshots, and local copies are treated as design choices to avoid, not as a convenience default.
If the client environment can log who saw which item, that log is part of the operating design. No universal audit product is claimed.
Contact us to discuss project-specific security requirements. The correct design for a public benchmark is not the correct design for unpublished clinical notes or live financial documents. Those differences should be settled before the first reviewer is onboarded.
Include the data class, the required environment, and any hard geographic limits in the first brief.