| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Effective date | August 2026 |
| Next review | August 2027 |
| Classification | Public |
1. Purpose
This policy sets out the security requirements that attach to people: what is verified before someone is trusted with access, the confidentiality obligations everyone works under, how access follows a person through joining, role change, and departure, and what happens when the rules are broken. People hold the credentials and the customer trust; this policy makes their lifecycle a controlled process rather than an informal one.
2. Scope
This policy applies to all Lever AI personnel — founders, employees, and contractors — and to any third party granted access to company systems or data. It covers the full engagement lifecycle: before joining, during employment or engagement, on change of role, and at and after departure.
3. Policy
3.1 Confidentiality agreements
A written confidentiality (non-disclosure) undertaking is a condition of employment and of any contractor or third-party engagement. No one is granted access to Confidential or Restricted information, as defined in the Data Classification Policy, before their confidentiality agreement is in place. Confidentiality obligations expressly cover customer data, customer and platform-vendor proprietary information, and company intellectual property, and they survive the end of employment or engagement.
3.2 Background verification
Every new hire, and every contractor being granted access to customer data or production systems, undergoes background verification proportionate to the role, where and to the extent lawful in the relevant jurisdiction: confirmation of identity, confirmation of the right to work, and reference checks covering recent employment or engagements. Additional checks may be applied for roles with privileged production access. This is the company's standard for all hiring from the effective date of this policy forward; it is not asserted as a description of hires made before that date, and verification is not applied retrospectively to existing personnel.
3.3 Joiners, movers, and leavers
Access follows a recorded joiner/mover/leaver checklist, executed by the Founder or a designated engineer as set out in the Access Control Policy. Completion of each checklist is recorded, so that who had access to what, and when, can always be established.
| Stage | Required steps | Timing |
|---|---|---|
| Joiner | Confidentiality agreement signed; background verification completed (section 3.2); Acceptable Use Policy accepted; security awareness training completed per the Security Awareness and Training Policy; access granted on least privilege per the Access Control Policy. | Before access to systems or customer data is granted. |
| Mover | Access rights re-assessed against the new role; access no longer needed is removed, not left to accumulate; new access granted on least privilege. | Access adjusted within 24 hours of the role change taking effect. |
| Leaver | All accounts disabled and access revoked across cloud, source-control, data-store, and customer-tenant systems; shared secrets and any credentials the leaver could have known are rotated; enrolled devices must be remotely revoked or wiped through the device management (MDM) tooling where it supports this, alongside — never in place of — that credential rotation; company devices and materials returned; continuing confidentiality obligations confirmed in writing. | Revocation within 24 hours of departure; sooner where the departure presents elevated risk. |
The quarterly access review required by the Access Control Policy acts as the backstop that catches anything the checklist missed.
3.4 During employment or engagement
All personnel work under the Acceptable Use Policy and the other policies of this suite, and complete security and privacy training on joining and at least annually thereafter, as required by the Security Awareness and Training Policy. Contractors and third parties are held to the same security obligations as employees through their contracts, and their access is time-bound to the engagement.
3.5 Disciplinary process
Breach of the company's security policies is a disciplinary matter. Consequences are proportionate to the severity and intent of the breach and range from documented counselling and retraining to withdrawal of access, termination of employment or contract, and, where warranted, legal action. Honest, promptly reported mistakes are treated as learning input under the Incident Response and Business Continuity Policy; concealment, repetition, or deliberate misuse is treated as serious misconduct. Disciplinary decisions are made by the Founder and recorded.
4. Responsibilities
The Founder is accountable for this policy, approves hires and engagements, and decides disciplinary outcomes. The Security Owner maintains the joiner/mover/leaver checklist, verifies its completion, and keeps the records. Whoever grants access under the Access Control Policy executes the access steps of the checklist. Every member of staff is responsible for meeting the obligations this policy attaches to their own employment or engagement, including completing required training on time.
5. Exceptions
Any exception to this policy must be requested in writing, assessed for risk, approved by the Founder, recorded, and limited in time. Expired exceptions lapse unless explicitly renewed.
6. Review
This policy is reviewed at least annually and whenever there is a significant change to the team, the business, or applicable employment law. The document owner maintains its version history.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI