| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Effective date | August 2026 |
| Next review | August 2027 |
| Classification | Public |
1. Purpose
This document defines who is accountable and responsible for information security at Lever AI, so that security is owned rather than assumed. Where the team is small, one person may hold several of these roles; what matters is that accountability is named and recorded.
2. Scope
This document covers all security-relevant roles across the company and the systems it operates, including the services it provides.
3. Roles
3.1 Executive sponsor
The Founder is accountable for information security overall, approves the security policies, and provides the resources to sustain the programme.
3.2 Security Owner
The Security Owner runs the security programme day to day. This includes maintaining the policies, leading risk assessment and treatment, coordinating incident response, managing access reviews and vulnerability tracking, assessing suppliers, and overseeing security awareness training.
3.3 Data Protection lead
The Data Protection lead is responsible for privacy compliance, data processing agreements, the sub-processor list, and requests from individuals about their personal data. In a small team this may be the same person as the Security Owner.
3.4 Engineering owner
The Engineering owner is responsible for secure implementation and operation of the product and infrastructure, including code review, dependency management, secrets handling, cloud configuration, logging and monitoring, and patching.
3.5 All personnel
Everyone is responsible for following the security policies, protecting credentials and data, and reporting suspected incidents promptly.
4. Responsibility summary
| Activity | Sponsor | Security Owner | Data Protection | Engineering | All staff |
|---|---|---|---|---|---|
| Approve policies | A | R | C | C | I |
| Maintain policies | I | A / R | C | C | I |
| Risk assessment and treatment | A | R | C | C | I |
| Access control and reviews | I | A | I | R | I |
| Incident response | A | R | C | R | I |
| Personal-data breach handling | A | R | A / R | C | I |
| Secure development and patching | I | A | I | R | I |
| Cloud and infrastructure security | I | A | I | R | I |
| Supplier and sub-processor risk | I | R | C | C | I |
| Security awareness and training | A | R | C | C | R |
| Data agreements and individual requests | A | C | R | I | I |
A: accountable. R: responsible. C: consulted. I: informed. Where the same person holds several roles, the named assignment is kept explicit.
5. Separation of duties
Where team size allows, sensitive actions such as approving a production change and deploying it are kept separate. Where full separation is not practical, compensating controls apply, including peer review of changes, logging of privileged actions, and management oversight.
6. Review
This document is reviewed at least annually and whenever the team structure or named owners change. Assignments are updated promptly when someone joins, moves, or leaves.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI