| Entity | AgentLayer Systems Private Limited (Lever AI) |
| Document owner | Security and Compliance, Lever AI |
| Approved by | Kshitij Arora, Founder, Lever AI |
| Effective date | August 2026 |
| Next review | August 2027 |
| Classification | Public |
1. Purpose
Lever AI delivers its service on top of a small number of third-party providers. This policy governs how those providers are chosen, what must be reviewed before any provider is allowed to touch customer data, how providers are re-reviewed while in use, and how the company's list of subprocessors is kept accurate. The subprocessor register in Appendix A is the authoritative, complete list of third parties that process customer data on Lever AI's behalf.
2. Scope
This policy applies to every third-party product or service used to build, operate, or support Lever AI's service, and to every person who introduces one. It distinguishes:
- Subprocessors — vendors that store, process, or can access customer data. These are subject to the full requirements of this policy and must appear in Appendix A;
- Other vendors — tools and services that do not touch customer data, which are subject to the lighter-weight approval in section 3.5.
The target HRIS platform and the customer's own environments are not Lever AI vendors: they belong to the customer, and access to them is governed by the terms of the engagement and the Information Security Policy, not by this policy.
3. Policy
3.1 Assessment method and proportionality
Lever AI is a founder-led company of single-digit headcount, and its subprocessors are large cloud and AI providers that publish independent certifications and attestations. The company's assessment method is therefore documentary: it reviews the provider's published certifications, attestations, and security documentation, and the contractual data-protection terms available to it, rather than conducting bespoke audits of the provider — which the company is not in a position to perform and does not claim to perform. Where a provider's published assurance is insufficient for the data involved, the provider is not used for that data.
3.2 The subprocessor register
Appendix A of this policy is the company's subprocessor register. It is the single authoritative list; the same list is used in customer contracts, security-questionnaire answers, and the company's privacy notice. No vendor may store, process, or access customer data unless it is listed in the register, and the register may be changed only after the onboarding review in section 3.3 has been completed and approved. For each subprocessor the register records its role, the customer data it processes, its processing location, and the published assurance relied upon. Removals are made when a provider is offboarded under section 3.7.
3.3 Onboarding review — before any new subprocessor
Before any new vendor stores, processes, or accesses customer data (or company data classified Confidential or Restricted under the Data Classification Policy), all of the following must be completed and recorded:
- Assurance review. A review of the provider's published security certifications and attestations (for example SOC 2 or ISO/IEC 27001) and security documentation, sufficient to conclude the provider can protect the data involved;
- Data-protection agreement. A data processing agreement, or equivalent contractual data-protection terms, must be in place with the provider wherever personal data will be processed, consistent with the Data Protection and Privacy Policy. For AI providers, the terms must exclude customer data from use in model training, as required by the AI Governance Policy;
- Data-flow note. A short written note recording what data the provider will receive, for what purpose, where it will be processed, and what the provider retains;
- Founder approval. The Founder's recorded approval of the vendor, after which the register in Appendix A is updated.
Introducing a vendor into the processing of customer data without this review is a policy breach, whatever the vendor's reputation.
3.4 Annual re-review
Every subprocessor in the register is re-reviewed at least annually. The re-review confirms that the provider's certifications and attestations remain current, checks for material changes to the provider's terms, security posture, or the data sent to it, considers any security incidents involving the provider, and re-confirms that the provider is still needed and receives no more data than the service requires. The outcome is recorded. Any concern the re-review cannot resolve is entered into the risk register under the Risk Management Policy with an owner and a treatment decision.
3.5 Vendors that do not touch customer data
Tools and services that will not store, process, or access customer data require approval before use for company work, as set out in the Acceptable Use Policy, and a proportionate check that they are reputable and appropriately secured. If the way a tool is used later changes such that customer data would reach it, it becomes a subprocessor and the full onboarding review in section 3.3 applies first.
3.6 Monitoring and provider incidents
Security advisories affecting subprocessor services are monitored under the Vulnerability Management Policy. A security incident at a provider that affects, or may affect, Lever AI or customer data is handled under the Incident Response and Business Continuity Policy, and triggers an out-of-cycle reassessment of the provider under this policy.
3.7 Offboarding
When a vendor is no longer used: its access and credentials are revoked, company and customer data held by it is retrieved or deleted in line with the Data Retention and Disposal Policy and the provider's terms, and the register is updated. Offboarding of a subprocessor is recorded.
4. Responsibilities
The Founder approves every subprocessor, every change to the register in Appendix A, and every annual re-review outcome. Any engineer who proposes or introduces a third-party dependency is responsible for routing it through this policy before customer data can reach it. Detailed security roles are set out in the Security Roles and Responsibilities document.
5. Exceptions
Exceptions to this policy require the Founder's written approval, a recorded rationale and compensating control, and an expiry date. There are no standing exceptions: no vendor processes customer data outside the register.
6. Review
This policy, including the register in Appendix A, is reviewed at least annually and whenever a subprocessor is added, changed, or removed.
Appendix A — Subprocessor register
| Subprocessor | Role | Customer data processed | Processing location | Assurance relied upon |
|---|---|---|---|---|
| Microsoft Azure | Cloud hosting and managed data services (App Service, Cosmos DB for MongoDB, Blob Storage, AKS) | All service data: conversations and transcripts, uploaded requirement documents and attachments, job state, telemetry, and the restricted credential store | United States (West US 2); regional options on request | Microsoft's published compliance portfolio (SOC 1/2/3, ISO/IEC 27001, 27017, 27018, PCI DSS, CSA STAR; Microsoft Trust Center) |
| Anthropic | AI model API (Claude) for the agent's reasoning | Conversation content and customer document content submitted for processing during agent runs; excluded from model training by default under Anthropic's commercial terms | United States | Anthropic's SOC 2 Type II attestation and published trust documentation |
| GitHub (Microsoft) | Source code hosting and CI | None — no customer data is stored in source control | Not applicable — no customer data processed | GitHub's published security and compliance documentation |
This register is complete as at the effective date of this policy. It changes only through the onboarding review in section 3.3 or the offboarding process in section 3.7, each with recorded Founder approval.
Approval and adoption
This policy has been reviewed and approved for adoption by Lever AI. It takes effect from the effective date shown in the document control table above and remains in force until it is reviewed or superseded.
Kshitij Arora
Founder, Lever AI