SECURITY & GOVERNANCE
Extract value from your data with confidence
Protecting customer data is our highest priority. Encord was built from the ground up with enterprise-grade security, governance, and compliance at every layer.
SECURITY & GOVERNANCE
Extract value from your data with confidence
Protecting customer data is our highest priority. Encord was built from the ground up with enterprise-grade security, governance, and compliance at every layer.
Trusted by leading AI teams
Uncompromised security and governance
Strict adherence to compliance standards
Encord maintains rigorous compliance with industry standards to protect your most sensitive data. Our platform is designed to safeguard personal information, protected health data, and valuable intellectual property through comprehensive security protocols and data handling practices that meet the highest regulatory requirements.
AICPA SOC 2
Encord has successfully completed its Systems and Organizational Control (SOC)-2 Examination. In doing so, Encord maintains its adherence to one of the most stringent, industry-accepted compliance frameworks for service organizations and provides additional assurance to its clients through an independent auditor that its business process, information technology, and risk management controls are properly designed.
HIPAA Compliant
Encord utilizes enterprise-grade best practices to protect our customers' sensitive health information and uses Vanta to verify its security, privacy, and HIPAA compliance controls. Vanta’s HIPAA product provides an automated approach to ensuring that organizations can demonstrate compliance.
GDPR Compliant
Encord maintains GDPR compliance through comprehensive security measures and responsible data handling practices. We continuously monitor our compliance status using Vanta's automated platform, ensuring our security controls and data protection standards consistently meet regulatory requirements while providing transparency and accountability.
By design, Encord’s platform does not store your data when using cloud integration. We offer a range of configuration options and recommend setting up Private Cloud Integration so that your data can remain stored and protected in your own cloud storage. This integration works by having our platform authorized to request a temporary, signed URL from your storage provider and then temporarily load the data into the end-user’s browser. Alternatively, you may opt to use the Encord platform directly to store your data, in which case, your data will be stored in Google Storage with all of the standard protections you would expect (Encryption at rest with AES-256, encryption in transit via HTTPS/TLS, no public access etc). Label data is also stored in the Encord database. It is encrypted at rest with AES-256 and encrypted in transit with HTTPS over TLS.
Using our Private Cloud Integration means our platform is authorized to request a signed URL from your storage provider and then temporarily load the data (images, videos, etc.) into the end-user’s browser, without it ever being processed or stored by the Encord platform itself. If you do not wish for Encord to sign your URL’s, you may use Direct Access. You can also use a Direct Access dataset that is available via private access points or where access to the cloud data is controlled, such as via IP whitelist. Choosing this option means you will not be able to secure your dataset behind user-based access controls. If you do not wish to allow Encord the ability to download any information (but still sign URL’s), you may take advantage of the Client Side Only integration option. In order to use this, you will need to supply additional metadata within the upload JSON file as described in our documentation. Client Side Only integrations can be configured in combination with the other private cloud integration options including Direct Access.
Data at rest is encrypted with Google Managed Keys and uses AES-256 encryption.
All data in transit is protected using HTTPS over TLS and we support the latest TLS encryption (version 1.3).
Visit our trust center (https://trust.encord.com/). For any other security-related inquiries, contact our dedicated security team at security@encord.com.
Case studies
Trusted by leading AI teams