| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Classification | Public |
1. Purpose
This policy sets out how Lever AI governs the use of artificial intelligence in its product. It defines accountability, the risks the company manages, and the controls it applies, so that AI is used responsibly, transparently, and under human control. It is aligned to the principles of ISO/IEC 42001.
2. Scope
This policy applies to all Lever AI personnel and to the AI components used in, or in connection with, the company's product. It covers the company's own software, the third-party AI services the product interoperates with, and the data handled through them.
3. Governance and accountability
The Founder holds executive accountability for the company's approach to AI, and this policy is approved at executive level. Kshitij Arora, Founder, is the named AI owner responsible for the governance of the AI components associated with the product. The company's AI governance is aligned to the principles of ISO/IEC 42001. The company is not currently pursuing ISO/IEC 42001 certification; it is pursuing SOC 2 Type 1 and ISO 27001.
4. How AI is used in the product
The company's product exposes a set of deterministic tools that let a user's own AI assistant carry out tasks against systems the user is authorised to use. The AI reasoning is performed by the user's chosen AI assistant, which the user operates and controls. Lever AI does not host, train, or fine-tune any AI model of its own. A register of the AI components in use is maintained at Appendix A.
5. Data governance for AI
The tools may handle the customer's own business data, which can include personal data and financial data, accessed on the authenticated user's behalf and processed only for the duration of a request. Lever AI does not retain this data at rest. Any data sent to an AI assistant is transmitted by the user's own assistant, under the user's agreement with that provider; Lever AI does not submit data to an AI provider and does not use any data to train a model. Operational logs record metadata only (the action, its status, and timing) and exclude credentials, tokens, and request or response content; these logs are retained for 90 days. Tools return only data within the user's authorised scope and never expose credentials.
6. AI risk management
The company identifies AI-related risks, assesses each by likelihood and impact, records it, and assigns treatment. The principal risks and their controls are:
- Incorrect or unintended action — mitigated by deterministic, scoped tools and by requiring explicit human confirmation before any action that changes or deletes data.
- Exposure of sensitive data — mitigated by least-privilege scoping, no retention of customer data at rest, and exclusion of credentials and content from logs.
- Prompt injection or manipulation — mitigated by validating tool inputs, enforcing the user's authorisation scope on every call, and keeping secrets out of the model context.
- Inaccurate model output — the quality of the underlying model is the provider's responsibility; the company limits the effect of any single output through deterministic tools and human confirmation.
7. Human oversight and control
A human remains in control of consequential actions: any action that changes or deletes data requires explicit user confirmation before it is carried out. The AI-driven capability can be disabled immediately by revoking the user's access or removing the connection. Where a user challenges or disputes an output, the concern is raised to the Security Owner, who can review it and, if needed, disable the affected capability.
8. Transparency and explainability
Every action taken through the tools is explicit and logged, with the tool, its inputs, and its result, giving an auditable trail of what was done. For the characteristics and limitations of the underlying models, the company refers to the model documentation published by the respective AI providers. Users are informed of significant changes to a model by the provider of the assistant they use.
9. AI incident management
AI-related events — including model failure, misuse of the AI capability, and any exposure of data through an AI output — are handled under the company's Incident Response and Business Continuity Policy. Where personal data is affected, the company notifies the affected customer without undue delay and follows the notification timelines set out in that policy. Any AI-related incident or near miss is recorded and reviewed.
10. Third-party AI and supply chain
The third-party AI providers and infrastructure the product relies on are listed in Appendix A. Providers are selected on the basis of a recognised security and privacy posture and are reviewed periodically. The AI assistant used at inference is engaged by the end user and is therefore not a Lever AI sub-processor; Lever AI relies on its infrastructure provider's data processing agreement for the hosting of its own service.
11. Training
Personnel involved in building or operating AI features receive guidance on responsible AI use, covering the controls in this policy, as part of the company's security awareness training.
12. Review
This policy is reviewed at least annually and whenever there is a significant change to the product, its AI components, or the applicable standards.
Appendix A — AI system register
| Component | Type | Provider | Role | Data exposure | Hosting |
|---|---|---|---|---|---|
| Product tool layer | Deterministic software tools | Lever AI | Exposes authorised systems as agent-callable actions | Customer data in transit; none at rest | Microsoft Azure (India, East US 2) |
| AI assistant | Third-party LLM, user-operated | Anthropic (Claude) | User's assistant that invokes the tools | Client-side, under the user's agreement | Provider / user side |
| AI assistant | Third-party LLM, user-operated | OpenAI (ChatGPT) | User's assistant that invokes the tools | Client-side, under the user's agreement | Provider / user side |
| Cloud infrastructure | Hosting | Microsoft Azure | Runs the product's services | Configuration and operational data | Azure (India, East US 2) |
Appendix B — AI impact assessment (summary)
Use of AI. The product lets a user's own AI assistant operate authorised systems in natural language through deterministic tools. Lever AI hosts and trains no model.
Data involved. The customer's own business data, which can include personal and financial data, processed only in transit and not retained; no data is used for model training.
Key risks considered. Incorrect or unintended action, exposure of sensitive data, prompt injection, and inaccurate model output.
Mitigations. Deterministic and scoped tools, human confirmation for actions that change data, least-privilege access, no customer data at rest, exclusion of credentials and content from logs, and instant disablement by revoking access.
Assessment. With these controls in place the residual risk is assessed as low. This assessment is reviewed at least annually and on any significant change.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI, effective 5 June 2026. It remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI