Compliance frameworks, security audits, and quality certifications this company maintains.
Scale AI maintains SOC 2 Type II certification across its data annotation and AI evaluation platforms, demonstrating rigorous controls over security, availability, and confidentiality of the sensitive customer training datasets processed through Scale Data Engine.
Scale AI's information security management system is ISO 27001 certified, covering the policies, processes, and controls that govern how Scale handles confidential AI training data, model outputs, and customer intellectual property across its global annotation workforce.
Regulatory
FedRAMP Moderate
In ProgressScale AI is pursuing FedRAMP Moderate authorization for Scale Donovan to meet U.S. federal procurement requirements, enabling broader deployment of its generative AI platform across civilian government agencies beyond current DoD program offices.
Scale AI's government division complies with CMMC (Cybersecurity Maturity Model Certification) Level 2 requirements, enabling it to handle Controlled Unclassified Information (CUI) for U.S. Department of Defense contracts awarded through Scale Donovan and defense data programs.
Scale AI complies with GDPR for annotation work performed by its European-based workforce and for processing personal data contained within training datasets provided by EU-based customers, with data processing agreements and data residency controls embedded in Scale Data Engine.
Scale AI adheres to CCPA requirements governing the collection and use of personal information belonging to California residents who work as taskers in Scale's annotation network or whose data appears in customer-provided training datasets processed on the platform.
Scale AI aligns Scale Donovan and Scale Evaluation to the NIST AI Risk Management Framework, providing government customers with structured AI risk identification, measurement, and governance documentation required by recent federal AI executive orders.
Scale AI's government division complies with International Traffic in Arms Regulations (ITAR) for defense-related AI programs, maintaining a U.S.-person-only workforce and access controls for annotation and evaluation tasks involving export-controlled technical data.
Scale AI signs Business Associate Agreements (BAAs) and applies HIPAA-compliant data handling controls when processing healthcare training datasets for medical AI customers, including de-identification verification and access logging through Scale Data Engine.
Scale AI is adapting its platform compliance posture to meet EU AI Act obligations as a provider of data and evaluation services used in high-risk AI system development, implementing transparency documentation and conformity assessment support for EU enterprise customers.