Trust & Security · Policy 03 of 21

Security Awareness and Training Policy

How Lever AI keeps its people aware of and trained on security.

EntityAgentLayer Systems Private Limited (Lever AI)
Document ownerSecurity and Compliance, Lever AI
Approved byKshitij Arora, Founder, Lever AI
Effective dateJune 2026
Next reviewJune 2027
ClassificationPublic

1. Purpose

This policy makes sure everyone at Lever AI understands their security responsibilities and can recognise and respond to common threats. It sets a consistent, recorded practice for security awareness rather than leaving it to chance.

2. Scope

This policy applies to all Lever AI personnel and to third parties with access to company systems or data.

3. Requirements

3.1 On joining

Every new joiner completes security awareness training within two weeks of joining and before being granted access to systems or data. The onboarding covers the company's security policies, acceptable use, data handling, and how to report an incident.

3.2 Ongoing

All personnel complete refresher training at least once a year. Awareness is reinforced with short updates when a notable threat or change arises.

3.3 Topics

Training covers, at a minimum: phishing and social engineering; strong authentication and use of multi-factor authentication; handling of personal and confidential data, including not placing sensitive data into AI prompts without authorisation; secure use of devices, cloud accounts, and secrets; and how to report a suspected incident quickly and without blame. Engineers receive additional guidance on secure development, and anyone operating AI features is briefed on responsible use, including that the service runs no model of its own and that data-changing actions require human confirmation.

3.4 Records

Completion of training is recorded, showing who completed what and when. These records are retained as evidence for audits and customer reviews. The Security Owner tracks completion and follows up where training is outstanding.

3.5 Non-completion

Where required training is not completed, access may be restricted until it is.

4. Responsibilities

The Security Owner owns the programme, sets the content, and tracks completion. Managers ensure their people complete their training. Every member of staff completes assigned training and applies it in their work.

5. Review

This policy is reviewed at least annually and updated as the business and threats evolve.

Approval and adoption

This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.

Kshitij Arora

Founder, Lever AI