Trust & Security · Policy 06 of 21

AI Governance Policy

How Lever AI governs the responsible use of artificial intelligence in its product.

EntityAgentLayer Systems Private Limited (Lever AI)
Document ownerSecurity and Compliance, Lever AI
Approved byKshitij Arora, Founder, Lever AI
ClassificationPublic

1. Purpose

This policy sets out how Lever AI governs the use of artificial intelligence in its product. It defines accountability, the risks the company manages, and the controls it applies, so that AI is used responsibly, transparently, and under human control. It is aligned to the principles of ISO/IEC 42001.

2. Scope

This policy applies to all Lever AI personnel and to the AI components used in, or in connection with, the company's product. It covers the company's own software, the third-party AI services the product interoperates with, and the data handled through them.

3. Governance and accountability

The Founder holds executive accountability for the company's approach to AI, and this policy is approved at executive level. Kshitij Arora, Founder, is the named AI owner responsible for the governance of the AI components associated with the product. The company's AI governance is aligned to the principles of ISO/IEC 42001. The company is not currently pursuing ISO/IEC 42001 certification; it is pursuing SOC 2 Type 1 and ISO 27001.

4. How AI is used in the product

The company's product exposes a set of deterministic tools that let a user's own AI assistant carry out tasks against systems the user is authorised to use. The AI reasoning is performed by the user's chosen AI assistant, which the user operates and controls. Lever AI does not host, train, or fine-tune any AI model of its own. A register of the AI components in use is maintained at Appendix A.

5. Data governance for AI

The tools may handle the customer's own business data, which can include personal data and financial data, accessed on the authenticated user's behalf and processed only for the duration of a request. Lever AI does not retain this data at rest. Any data sent to an AI assistant is transmitted by the user's own assistant, under the user's agreement with that provider; Lever AI does not submit data to an AI provider and does not use any data to train a model. Operational logs record metadata only (the action, its status, and timing) and exclude credentials, tokens, and request or response content; these logs are retained for 90 days. Tools return only data within the user's authorised scope and never expose credentials.

6. AI risk management

The company identifies AI-related risks, assesses each by likelihood and impact, records it, and assigns treatment. The principal risks and their controls are:

  • Incorrect or unintended action — mitigated by deterministic, scoped tools and by requiring explicit human confirmation before any action that changes or deletes data.
  • Exposure of sensitive data — mitigated by least-privilege scoping, no retention of customer data at rest, and exclusion of credentials and content from logs.
  • Prompt injection or manipulation — mitigated by validating tool inputs, enforcing the user's authorisation scope on every call, and keeping secrets out of the model context.
  • Inaccurate model output — the quality of the underlying model is the provider's responsibility; the company limits the effect of any single output through deterministic tools and human confirmation.

7. Human oversight and control

A human remains in control of consequential actions: any action that changes or deletes data requires explicit user confirmation before it is carried out. The AI-driven capability can be disabled immediately by revoking the user's access or removing the connection. Where a user challenges or disputes an output, the concern is raised to the Security Owner, who can review it and, if needed, disable the affected capability.

8. Transparency and explainability

Every action taken through the tools is explicit and logged, with the tool, its inputs, and its result, giving an auditable trail of what was done. For the characteristics and limitations of the underlying models, the company refers to the model documentation published by the respective AI providers. Users are informed of significant changes to a model by the provider of the assistant they use.

9. AI incident management

AI-related events — including model failure, misuse of the AI capability, and any exposure of data through an AI output — are handled under the company's Incident Response and Business Continuity Policy. Where personal data is affected, the company notifies the affected customer without undue delay and follows the notification timelines set out in that policy. Any AI-related incident or near miss is recorded and reviewed.

10. Third-party AI and supply chain

The third-party AI providers and infrastructure the product relies on are listed in Appendix A. Providers are selected on the basis of a recognised security and privacy posture and are reviewed periodically. The AI assistant used at inference is engaged by the end user and is therefore not a Lever AI sub-processor; Lever AI relies on its infrastructure provider's data processing agreement for the hosting of its own service.

11. Training

Personnel involved in building or operating AI features receive guidance on responsible AI use, covering the controls in this policy, as part of the company's security awareness training.

12. Review

This policy is reviewed at least annually and whenever there is a significant change to the product, its AI components, or the applicable standards.

Appendix A — AI system register

ComponentTypeProviderRoleData exposureHosting
Product tool layerDeterministic software toolsLever AIExposes authorised systems as agent-callable actionsCustomer data in transit; none at restMicrosoft Azure (India, East US 2)
AI assistantThird-party LLM, user-operatedAnthropic (Claude)User's assistant that invokes the toolsClient-side, under the user's agreementProvider / user side
AI assistantThird-party LLM, user-operatedOpenAI (ChatGPT)User's assistant that invokes the toolsClient-side, under the user's agreementProvider / user side
Cloud infrastructureHostingMicrosoft AzureRuns the product's servicesConfiguration and operational dataAzure (India, East US 2)

Appendix B — AI impact assessment (summary)

Use of AI. The product lets a user's own AI assistant operate authorised systems in natural language through deterministic tools. Lever AI hosts and trains no model.

Data involved. The customer's own business data, which can include personal and financial data, processed only in transit and not retained; no data is used for model training.

Key risks considered. Incorrect or unintended action, exposure of sensitive data, prompt injection, and inaccurate model output.

Mitigations. Deterministic and scoped tools, human confirmation for actions that change data, least-privilege access, no customer data at rest, exclusion of credentials and content from logs, and instant disablement by revoking access.

Assessment. With these controls in place the residual risk is assessed as low. This assessment is reviewed at least annually and on any significant change.

Approval and adoption

This policy has been reviewed and approved for adoption by Lever AI, effective 5 June 2026. It remains in force until it is reviewed or superseded.

Kshitij Arora

Founder, Lever AI