Short answer. Annotation security is not a software question, because a human being has to look at the data. The security boundary therefore includes the platform, storage, network, identity controls, the production facility and the annotator's physical working environment — and most certification portfolios cover only the first few. Evaluate seven things: data residency, access management, encryption, physical controls where the data warrants them, named subprocessors, incident response and a documented deletion path. Ask for every certificate together with its scope statement, because scope is where these usually fall apart.
Annotation exposes human workers to proprietary images, customer conversations, medical information, maps, source code, product plans and internal documents. That is the whole point of the service. It also means that a SOC 2 report describing a cloud platform, however good, describes a subset of your actual exposure.
This guide sets out what to evaluate, what evidence to require for each item, and where enterprise security reviews of annotation vendors typically go wrong.
The seven control areas
| Security area | Enterprise requirement | Procurement evidence |
|---|---|---|
| Data residency | Restrict processing to approved geography | Contractual and technical geographic controls |
| Access management | Least privilege, rapid revocation | RBAC, identity verification, audit logs |
| Encryption | Protection in transit and at rest | Documented encryption controls and key management |
| Physical security | Controlled worker environment where needed | Secure centres, authentication, device restrictions |
| Subprocessors | Visibility into third parties | Current subprocessor list and flow-down obligations |
| Certifications | Relevant independent controls | SOC 2, ISO 27001 and sector standards, with scope statements |
| Incident response | Defined breach and escalation process | Response plan and contractual notification windows |
| Data deletion | Retention and disposal rules | Documented lifecycle controls and deletion confirmation |
Where security reviews of annotation vendors go wrong
Reading the logo instead of the scope. A certification covering a corporate head office says nothing about the delivery centre where your data will be viewed. Request the certificate and the scope statement together, every time, and check that the scope names the location and service you are actually buying. This single check disqualifies more vendors than any other.
Treating platform controls as complete. Encryption at rest, SSO and audit trails protect data in a system. They do not address what happens on the screen a human is looking at, or the phone in their pocket. Both control families are necessary and they are assessed separately.
Accepting "we are GDPR compliant" as a control. Regulatory alignment is a claim about a legal position, not a description of a technical or physical control. Ask what the vendor does, specifically, that implements it: where data is stored, who can access it, how consent and lawful basis are evidenced, what the deletion path is.
Not asking about subprocessors. Annotation vendors subcontract. That is not a scandal; an undisclosed subcontractor is. Ask for the current list, the flow-down obligations, and the notification process when it changes.
Deferring the residency question to the contract stage. Whether work can be confined to a named jurisdiction is an architectural property of the vendor's operating model, not a clause. Find out early — it eliminates shortlists.
Physical and workforce controls: the part software cannot cover
Where the data is sensitive, ask specifically:
- Are annotators remote, in controlled facilities, or a mix? A mixed model is common and is fine, provided you know which of your data goes to which.
- What device controls are enforced? Personal devices, phones, cameras, USB ports, screenshots, copy and paste, printing, and the network the workstation sits on.
- How is identity verified at the point of work? Badge, biometric, two-factor, and whether the same person is verified as being at the workstation for the duration.
- How quickly is access revoked after reassignment or termination — and is revocation verified rather than requested?
- Is work segregated by project and by client? Ask how, not whether.
- Who supervises the room? The most sensitive programmes need a named supervisor and a physical access log, not a policy.
Note that these questions apply differently to a crowd model and a centre model. Neither is inherently more secure; they fail differently. A crowd model has a larger, less verifiable population with less environmental control. A centre model concentrates risk in fewer locations with more control and a clearer audit trail. Match the model to the sensitivity of the data rather than to a preference.
Data residency: what to require
Residency is where legal requirements and operating models collide most often.
- Can processing be confined to a named country or region, and is that enforced technically as well as contractually?
- Does "processing" include viewing? A dataset stored in the EU but reviewed by an annotator elsewhere has left the region in every sense that matters.
- Do subprocessors inherit the restriction? Flow-down is where residency guarantees usually leak.
- What happens to backups, logs and derived artefacts? Gold sets, QA records and training extracts are data too.
- How is compliance evidenced? A report you can request, or an assurance you can only believe.
What other providers publish
Several annotation vendors publish detailed compliance portfolios, and for buyers whose security review is the gating step these are worth reading directly:
- SuperAnnotate publishes SOC 2 Type II, ISO 27001:2022, GDPR and CCPA controls, along with encryption, restricted production access and a current subprocessor list.
- iMerit publishes SOC 2 Type 2, ISO 27001, GDPR and TISAX compliance, with stated access controls and audit trails.
- Sama publishes ISO-certified delivery centres, biometric authentication, two-factor authentication, ISO 42001, GDPR and TISAX-related controls.
If a specific certification is mandatory for your programme, make it a pass/fail RFP requirement and verify the scope covers the platform, location and service you will actually use. If it is desirable rather than mandatory, score it — but score the scope, not the badge.
How Lifewood approaches this
Lifewood's relevant property here is structural rather than a certificate list: work is delivered through 40+ owned delivery centres across 30+ countries, which gives procurement an operational control point that a purely remote pool does not offer. A named facility can be inspected, access-logged, device-restricted and supervised; a distributed crowd cannot.
That footprint is also what makes geographic scoping possible. Distributed capacity supports client-mandated data residency — including confining processing to a specified region, enforced through geographic access controls and contractual flow-down to subprocessors — because there is somewhere specific for the work to happen.
For global AI products, the combination that matters is residency options alongside 50+ languages of native-speaker capability, so localisation and controlled processing are not a trade-off. Data-protection regime coverage, certification scope and physical controls should be scoped and evidenced per engagement rather than assumed from a footer badge — including for Lifewood. Ask for the scope statement here too.
Sources and further reading
- SuperAnnotate publishes its security and compliance posture at superannotate.com; iMerit at imerit.net; Sama at sama.com. All are company-published statements and should be requested with scope statements.
- Lifewood delivery figures (50+ languages, 40+ delivery centres across 30+ countries) published on lifewood.com.
- Related reading: 9 criteria for choosing AI annotation services covers security as one of nine evaluation dimensions.

