| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Effective date | August 2026 |
| Next review | August 2027 |
| Classification | Public |
1. Purpose
This policy states how Lever AI manages physical security. The company operates no data centres, server rooms, or on-premises production equipment of its own, and its people work remote-first; physical security therefore consists of the controls inherited from the company's cloud provider and the rules its people follow for the devices and workspaces they use. This policy sets out both, and is deliberately brief in proportion to that footprint.
2. Scope
This policy applies to all Lever AI personnel and to any contractor acting on the company's behalf. It covers the facilities that host the company's production services, the devices used to perform company work, and the physical environments in which that work is done.
3. Policy
3.1 Facilities and data centres
Production services run entirely on Microsoft Azure. Physical security of the underlying facilities — site access control, surveillance, environmental protection, and hardware handling and disposal — is provided by Microsoft and inherited by Lever AI, and is covered by Microsoft's published, independently audited compliance portfolio (including SOC 1, SOC 2, and SOC 3 attestations and ISO/IEC 27001 certification, as documented on the Microsoft Trust Center). Lever AI personnel have no physical access to these facilities, and the company relies on the provider's controls under the Vendor and Third-Party Risk Management Policy rather than operating physical data-centre controls of its own.
Where the customer-hosted execution mode is used, the execution component runs on infrastructure inside the customer's own environment; physical security of that infrastructure is the customer's responsibility.
3.2 Work devices
Endpoint laptops and desktops used for company work are managed through the company's mobile device management (MDM) system. Management covers corporate laptops and desktops together with the personal (BYOD) laptops permitted for company work, and the MDM enforces automatic screen locking, operating-system patch compliance, and the presence of an antimalware/EDR agent on every managed device. Central enforcement and attestation of full-disk encryption, host firewall configuration, and the restriction of local administrative rights are not yet provided through the MDM; all three are committed items on the company's security roadmap.
Enrolment must come before access: a device must be enrolled in the MDM before it is used to reach production systems, cloud environments, or service credentials. A personal (BYOD) laptop may be used for company work only if it is enrolled in the MDM and meets the same security baseline as a corporate device. A device that falls out of compliance with this section must have its access reviewed, and that access may be revoked until the device is brought back into compliance.
Devices used for company work must have full-disk encryption enabled, must lock automatically after no more than five minutes of inactivity, and must require a passcode or equivalent local credential to unlock, with credentials managed under the Password Policy. Central attestation of full-disk encryption through the MDM is a roadmap control; until it is in place, each device holder affirms compliance at the quarterly access review under the Access Control Policy.
Mobile phones must not be used to access production systems or service credentials, and any mobile device used for work communications must have a passcode set and must lock automatically. Where the MDM supports it, remote revocation and wipe must be applied when a device is lost or stolen or its holder leaves the company, always accompanied by rotation of the credentials reachable from the device. Loss-of-device risk is treated as a credentials risk: what matters is that a lost device yields neither data nor access, which the encryption, locking, wipe, and revocation rules in this section and section 3.5 together provide.
3.3 Removable media
Customer data is not stored on removable media (USB drives, external disks, or similar). Customer data lives only in the service's managed stores, handled according to its class under the Data Classification Policy.
3.4 Working in shared and public spaces
When working anywhere others could observe — co-working spaces, cafes, transit — screens are locked whenever a device is left unattended, sensitive information is kept from overlooking and overhearing, and a clean-desk discipline applies: no customer or Restricted information is left visible or unattended, on screen or on paper.
3.5 Loss or theft of a device
The loss or theft of any device used for company work is reported to the Security Owner within 24 hours of discovery. The report triggers rotation of the credentials and revocation of the sessions reachable from that device; where the device is enrolled in the MDM and the MDM supports it, a remote revoke and wipe of the device must also be issued — the wipe accompanies the credential rotation and never substitutes for it. The event is handled as a security incident under the Incident Response and Business Continuity Policy.
4. Responsibilities
The Security Owner owns this policy, verifies device compliance as part of the access reviews under the Access Control Policy, and coordinates the response to lost or stolen devices. Every member of staff is responsible for the physical care of the devices and information in their custody and for reporting losses promptly.
5. Exceptions
Any exception to this policy must be requested in writing, assessed for risk, limited in time, approved by the Founder, and recorded together with the compensating controls that apply while it stands.
6. Review
This policy is reviewed at least annually and whenever there is a significant change to the company's working arrangements or hosting. The document owner maintains its version history.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI