SuperAnnotate Trust Center

Transparency you can build on

Review the standards, controls, and third parties behind our commitment to the confidentiality, integrity, and availability of your data.

Controls continuously monitored Verified through Secureframe

SOC 2

Type II

Controls for security, availability, and confidentiality.

ISO

27001:2022

A globally recognized framework for information security management.

GDPR

Privacy

Protection of personal data and privacy for people in the European Union.

CCPA

Privacy

Data privacy protections for California residents.

Independent assurance

Controls backed by recognized standards

Our information security program is assessed against widely recognized security and privacy frameworks.

SOC 2

Type II

SOC 2

Controls for security, availability, and confidentiality.

ISO

27001:2022

ISO

A globally recognized framework for information security management.

GDPR

Privacy

GDPR

Protection of personal data and privacy for people in the European Union.

CCPA

Privacy

CCPA

Data privacy protections for California residents.

Subprocessors

The services that support our platform

Our Trust Center maintains the current list of third-party services involved in delivering and supporting SuperAnnotate.

View current subprocessor list
  • AWS Cloud infrastructure
  • Atlassian Development and operations
  • Google Workspace Business communication
  • Slack Internal communication
  • HubSpot Customer relationship management
  • Mixpanel Product analytics
  • Hotjar User experience analytics
  • Zendesk Customer support
Continuous monitoring

A living security program

Our controls are continuously monitored through Secureframe across the areas that matter most to customers.

Change management

  • Production data use is restricted
  • Secure development policy
  • Segregation of environments

Availability

  • Backup restoration testing
  • Uptime and availability monitoring
  • Business continuity planning

Access security

  • Access to product is restricted
  • Encryption and key management
  • Removal of access

Vulnerability management

  • Vulnerability and patch management
  • Third-party penetration testing

Network security

  • Endpoint security
  • Automated security alerts
  • Network security policy

Risk and response

  • Vendor risk management
  • Formal risk assessments
  • Incident response plan
Assurance resources

Documents for your review

Access public certifications and request restricted assurance documents through our verified Trust Center.

Certification

ISO/IEC 27001:2022

Our information security management system certification against the globally recognized ISO 27001 standard.

View resource
Independent report

SOC 2 Type II

An independent assessment of controls related to security, availability, and confidentiality over time.

Request report
Security assessment

Penetration Test Report

A report from regular third-party testing of our systems and controls, available through a controlled request.

Request report

Have a security question?

Our team can help with due diligence, document requests, and questions about how SuperAnnotate protects your data.