Trust & Security · Policy 04 of 21

Security Roles and Responsibilities

Who is accountable and responsible for security at Lever AI.

EntityAgentLayer Systems Private Limited (Lever AI)
Document ownerSecurity and Compliance, Lever AI
Approved byKshitij Arora, Founder, Lever AI
Effective dateAugust 2026
Next reviewAugust 2027
ClassificationPublic

1. Purpose

This document defines who is accountable and responsible for information security at Lever AI, so that security is owned rather than assumed. Where the team is small, one person may hold several of these roles; what matters is that accountability is named and recorded.

2. Scope

This document covers all security-relevant roles across the company and the systems it operates, including the services it provides.

3. Roles

3.1 Executive sponsor

The Founder is accountable for information security overall, approves the security policies, and provides the resources to sustain the programme.

3.2 Security Owner

The Security Owner runs the security programme day to day. This includes maintaining the policies, leading risk assessment and treatment, coordinating incident response, managing access reviews and vulnerability tracking, assessing suppliers, and overseeing security awareness training.

3.3 Data Protection lead

The Data Protection lead is responsible for privacy compliance, data processing agreements, the sub-processor list, and requests from individuals about their personal data. In a small team this may be the same person as the Security Owner.

3.4 Engineering owner

The Engineering owner is responsible for secure implementation and operation of the product and infrastructure, including code review, dependency management, secrets handling, cloud configuration, logging and monitoring, and patching.

3.5 All personnel

Everyone is responsible for following the security policies, protecting credentials and data, and reporting suspected incidents promptly.

4. Responsibility summary

ActivitySponsorSecurity OwnerData ProtectionEngineeringAll staff
Approve policiesARCCI
Maintain policiesIA / RCCI
Risk assessment and treatmentARCCI
Access control and reviewsIAIRI
Incident responseARCRI
Personal-data breach handlingARA / RCI
Secure development and patchingIAIRI
Cloud and infrastructure securityIAIRI
Supplier and sub-processor riskIRCCI
Security awareness and trainingARCCR
Data agreements and individual requestsACRII

A: accountable. R: responsible. C: consulted. I: informed. Where the same person holds several roles, the named assignment is kept explicit.

5. Separation of duties

Where team size allows, sensitive actions such as approving a production change and deploying it are kept separate. Where full separation is not practical, compensating controls apply, including peer review of changes, logging of privileged actions, and management oversight.

6. Review

This document is reviewed at least annually and whenever the team structure or named owners change. Assignments are updated promptly when someone joins, moves, or leaves.

Approval and adoption

This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.

Kshitij Arora

Founder, Lever AI