Trust & Security · Policy 01 of 21

Information Security Policy

The top-level policy of the Lever AI information security programme.

EntityAgentLayer Systems Private Limited (Lever AI)
Document ownerSecurity and Compliance, Lever AI
Approved byKshitij Arora, Founder, Lever AI
Effective dateJune 2026
Next reviewJune 2027
ClassificationPublic

1. Purpose

This policy states how Lever AI protects the confidentiality, integrity, and availability of the information and systems it operates, and the security obligations that apply to everyone who works for or on behalf of the company. It is the top-level policy of the Lever AI security programme. The supporting policies on data protection, access, incident response, and business continuity sit beneath it.

2. Scope

This policy applies to all Lever AI personnel and to any contractor or third party acting on the company's behalf. It covers all information the company creates, processes, stores, or transmits, and all systems and infrastructure it operates, including the services it provides and their supporting cloud environment on Microsoft Azure.

3. Security principles

3.1 Governance

Management is committed to information security and provides the resources needed to maintain it. Security responsibilities are assigned to named individuals. This policy and its supporting policies are reviewed at least once a year and after any significant change to the business, technology, or threat environment.

3.2 Risk management

The company identifies and assesses security risks on a recurring basis and decides how to treat them. Treatment decisions and their owners are recorded.

3.3 Data handling and minimisation

Information is handled according to its sensitivity, using the classification scheme in the Data Protection and Privacy Policy. The company's services are built to hold as little as possible. They run statelessly and do not store customer credentials, do not store access or refresh tokens, and do not retain end-user personal data. Customer data is processed only for the duration of a request and is not persisted afterwards.

3.4 Access control

Access to systems and data is granted on the principle of least privilege and only where there is a business need. Access is tied to individual identities, and shared accounts are avoided. Administrative and cloud-console access requires multi-factor authentication. End-user access to connected systems through the service is authorised for each user through OAuth 2.1 with PKCE, with the upstream system acting as the authorisation server; the service can only perform actions the user's own role permits. Access rights are reviewed on a quarterly basis and revoked promptly when someone leaves or changes role.

3.5 Cryptography and key management

Data in transit is protected using TLS 1.2 or above on all external endpoints. Secrets and keys are held in a managed secrets store and are never embedded in source code. Token authenticity is verified against the authorisation server's published signing keys.

3.6 Operations and cloud security

Production services run on Microsoft Azure, and the company relies on Azure's certified physical and platform controls. Systems are logged and monitored. Logs record operational information such as the action performed, its status, and timing, and do not contain credentials, tokens, or the content of requests and responses.

3.7 Secure development

Changes are peer-reviewed before release. Security is considered throughout development, and third-party dependencies are monitored for known vulnerabilities and updated in good time.

3.8 Use of artificial intelligence

The service does not run any AI model of its own. AI reasoning is carried out by the end user's own AI client under the user's agreement with the relevant provider. Actions that change or delete data require explicit human confirmation before they are carried out. Tool inputs are validated and limited to the authorised scope, and any session can be revoked immediately.

3.9 Incident management

Suspected security events are reported without delay and managed under the Incident Response Policy. Events affecting personal data are handled in line with the Data Protection and Privacy Policy and applicable law.

3.10 Business continuity

Recovery objectives, backups, and continuity arrangements are set out in the Business Continuity and Disaster Recovery Policy.

3.11 Suppliers

Providers with access to company systems or data are assessed before engagement and monitored afterwards. The primary infrastructure provider is Microsoft Azure.

4. Responsibilities

A named Security Owner is accountable for the security programme. Every member of staff is responsible for following this policy, protecting the information and credentials in their care, and reporting anything that looks wrong. Detailed assignments are set out in the Security Roles and Responsibilities document.

5. Compliance

Compliance with this policy is mandatory. Breaches may lead to disciplinary action and, where warranted, legal action. Any exception must be requested in writing, assessed for risk, limited in time, and approved by the Security Owner.

6. Review

This policy is reviewed at least annually and whenever there is a significant change. The document owner maintains its version history.

Approval and adoption

This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.

Kshitij Arora

Founder, Lever AI