| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Effective date | June 2026 |
| Next review | June 2027 |
| Classification | Public |
1. Purpose
This policy states how Lever AI protects the confidentiality, integrity, and availability of the information and systems it operates, and the security obligations that apply to everyone who works for or on behalf of the company. It is the top-level policy of the Lever AI security programme. The supporting policies on data protection, access, incident response, and business continuity sit beneath it.
2. Scope
This policy applies to all Lever AI personnel and to any contractor or third party acting on the company's behalf. It covers all information the company creates, processes, stores, or transmits, and all systems and infrastructure it operates, including the services it provides and their supporting cloud environment on Microsoft Azure.
3. Security principles
3.1 Governance
Management is committed to information security and provides the resources needed to maintain it. Security responsibilities are assigned to named individuals. This policy and its supporting policies are reviewed at least once a year and after any significant change to the business, technology, or threat environment.
3.2 Risk management
The company identifies and assesses security risks on a recurring basis and decides how to treat them. Treatment decisions and their owners are recorded.
3.3 Data handling and minimisation
Information is handled according to its sensitivity, using the classification scheme in the Data Protection and Privacy Policy. The company's services are built to hold as little as possible. They run statelessly and do not store customer credentials, do not store access or refresh tokens, and do not retain end-user personal data. Customer data is processed only for the duration of a request and is not persisted afterwards.
3.4 Access control
Access to systems and data is granted on the principle of least privilege and only where there is a business need. Access is tied to individual identities, and shared accounts are avoided. Administrative and cloud-console access requires multi-factor authentication. End-user access to connected systems through the service is authorised for each user through OAuth 2.1 with PKCE, with the upstream system acting as the authorisation server; the service can only perform actions the user's own role permits. Access rights are reviewed on a quarterly basis and revoked promptly when someone leaves or changes role.
3.5 Cryptography and key management
Data in transit is protected using TLS 1.2 or above on all external endpoints. Secrets and keys are held in a managed secrets store and are never embedded in source code. Token authenticity is verified against the authorisation server's published signing keys.
3.6 Operations and cloud security
Production services run on Microsoft Azure, and the company relies on Azure's certified physical and platform controls. Systems are logged and monitored. Logs record operational information such as the action performed, its status, and timing, and do not contain credentials, tokens, or the content of requests and responses.
3.7 Secure development
Changes are peer-reviewed before release. Security is considered throughout development, and third-party dependencies are monitored for known vulnerabilities and updated in good time.
3.8 Use of artificial intelligence
The service does not run any AI model of its own. AI reasoning is carried out by the end user's own AI client under the user's agreement with the relevant provider. Actions that change or delete data require explicit human confirmation before they are carried out. Tool inputs are validated and limited to the authorised scope, and any session can be revoked immediately.
3.9 Incident management
Suspected security events are reported without delay and managed under the Incident Response Policy. Events affecting personal data are handled in line with the Data Protection and Privacy Policy and applicable law.
3.10 Business continuity
Recovery objectives, backups, and continuity arrangements are set out in the Business Continuity and Disaster Recovery Policy.
3.11 Suppliers
Providers with access to company systems or data are assessed before engagement and monitored afterwards. The primary infrastructure provider is Microsoft Azure.
4. Responsibilities
A named Security Owner is accountable for the security programme. Every member of staff is responsible for following this policy, protecting the information and credentials in their care, and reporting anything that looks wrong. Detailed assignments are set out in the Security Roles and Responsibilities document.
5. Compliance
Compliance with this policy is mandatory. Breaches may lead to disciplinary action and, where warranted, legal action. Any exception must be requested in writing, assessed for risk, limited in time, and approved by the Security Owner.
6. Review
This policy is reviewed at least annually and whenever there is a significant change. The document owner maintains its version history.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI