SECURITY AND PRIVACY
What your security team needs to see.
Before anyone signs, someone on your side asks for documents. Where the data lives, who touches it, what happens if it leaks, whether the model learns from what your company sends. This page answers all of it in one link.
No badge we do not hold, and no promise the contract does not cover. What is here is what actually runs, and every document named exists and can be requested.
Last updated: July 22, 2026
POSTURE
Six decisions that come before the project.
These are not features of an expensive plan. They are the rules every engagement starts with.
Isolation per client
Every client on a dedicated instance. No data mixed across accounts, by architecture, not by configuration.
Encryption always
TLS 1.3 in transit and AES 256 at rest, on every system that stores personal data.
Zero training on your data
Your data trains no model, ours or anyone else's. It is a clause with you and with the model provider.
Least privilege
Access by role, mandatory MFA on admin access, and database roles with the minimum needed to work.
The final decision is human
Nothing with material impact is decided by the machine alone. That is LGPD article 20, and it is also how we design.
Legal basis before processing
We turn down engagements that depend on processing data without a clear legal basis. Better to say no than to fix it later.
ROLES
Who answers for what.
Under LGPD, the controller decides the purpose and the processor acts on the controller's instructions. In Levver products, your company is the controller of the data and Levver is the processor. Levver is controller only of product telemetry and of the data from people who contact us through the site.
Levver's responsibility
- ·Infrastructure, isolation and encryption.
- ·Access logging on sensitive data.
- ·Backup, recovery and continuity.
- ·Incident response, with declared deadlines.
- ·DPA, subprocessor list, and notice when that list changes.
- ·Assisting you when a data subject exercises a right.
Your company's responsibility
- ·Defining the purpose and the legal basis of the processing.
- ·Deciding who on your team has access, and removing it when someone leaves.
- ·Notifying your own data subjects when the law requires it.
- ·Setting the retention policy your business needs.
- ·Keeping the data you send us within what was agreed.
GOVERNANCE
The document exists, has an owner and has a date.
A policy with no owner and no date is decoration. Ours are approved, versioned and reviewed at least once a year, or sooner if the architecture changes. They are available for your vendor assessment.
Information Security Policy
Principles, controls, responsibilities, and what to do when something falls outside the standard.
Information classification
Which level of data requires which treatment, from public to restricted, and how that drives access, encryption and retention.
International transfer
When data leaves Brazil, under which safeguard, and which LGPD article 33 mechanism applies in each case.
Data protection impact assessment (DPIA)
LGPD article 38. Done for the product's core processing and for the voice operation, which handles sensitive data.
Records of processing activities (ROPA)
LGPD article 37, in the format published by the Brazilian data protection authority, kept for the operation that handles sensitive data.
Data Processing Agreement (DPA)
A mandatory clause in the contract, covering purpose, subprocessors, security measures, assistance, and return or deletion at the end.
Backup and recovery runbook
Strategy per component, with declared RPO and RTO, and restore testing with evidence.
Incident response runbook
Severity classification, step by step decisions, and a communication deadline for each party.
Data protection officer appointed, João Prado, at dpa@levver.ai.
ENGINEERING
What stops the code before it gets anywhere near your data.
Security that depends on someone remembering is not security. Ours sits on the mandatory path of the code that handles client data.
Dependency audit and static analysis
They run on every change and block the merge. Not a yellow warning, a closed door.
Typing and lint at the same gate
An entire class of error dies before it becomes behavior in production.
Secrets in a managed vault
Never in the code, never in a loose variable, never in a chat message.
A dedicated identity per service
Each service runs with its own identity and the minimum permission it needs to work.
Tests never run against production
Separate environment, its own test data. Production is not a laboratory.
Code in your repository
On custom projects, from day one. You never depend on our goodwill to hold what you paid for.
THE DATA
Where it lives, how long, who touches it.
Where it lives
The region is defined per project and written into the DPA. The site runs in São Paulo. In the products, the processing region is declared in the DPA, and today part of the infrastructure runs outside Brazil, which includes the AI model providers. In those cases the LGPD article 33 safeguard applies, with equivalent contractual clauses and, where applicable, the standard clauses published by the Brazilian authority. Data residency in Brazil is assessed and set in the contract.
How long
Retention is defined per data type and recorded, not improvised. Audit records have long retention by legal requirement, operational data lives for the term of the contract, and data from people who only contacted us through the site lives for the term of the commercial relationship.
Who touches it
Access by role, with mandatory MFA on admin access. Access to sensitive data is logged, and in our products that log is immutable by database design.
When it ends
Return or deletion of the data at the end of the contract, as set in the DPA. Your exit is not tied to our calendar.
CONTINUITY
What happens when something goes wrong.
Every vendor promises nothing will happen. The useful question is a different one, what is written down for the day it does.
Backup and point in time
Automated daily backup and recovery to any point inside a seven day window.
Declared RPO and RTO
Per component, in the runbook. On the product database, maximum loss is measured in minutes and expected recovery is one to two hours.
Restore testing with evidence
Periodic, on an isolated instance, without touching production. The last one ran in June 2026 and is on record.
Incident communication deadlines
When personal data is involved, the authority within 72 hours, the affected data subject within 48 hours, and the client within 24 hours.
Root cause, always
Every critical event ends in a root cause analysis with a preventive action, not in an explanation.
RESPONSIBLE AI
The line we do not cross.
- ·The final decision is always human. Nothing with material impact is decided by the machine alone.
- ·Client data trains no model, neither ours nor the provider's.
- ·Content sent to the model API is discarded after inference, by agreement with the provider.
- ·We tell you where the AI fails and where human review is needed, before you find out on your own.
- ·Model providers go on the subprocessor list and meet the same bar as everyone else.
SUBPROCESSORS
Who the data passes through.
A short list by choice. Every provider comes in with contractual commitments equivalent to or stronger than LGPD requires. When this list changes, clients are notified.
| Provider | What for | Where |
|---|---|---|
| Google Cloud and Firebase | Hosting, database, authentication and site analytics | São Paulo, or the region defined in the project |
| Amazon AWS | Hosting, when the client's project calls for it | Region defined in the project |
| Anthropic, OpenAI, Google and Microsoft | Content processing by AI models, with no training and discarded after inference | United States, under the article 33 safeguard |
| Google reCAPTCHA | Protecting the site form against bots | United States |
| Google Workspace | Corporate communication and delivery of the contact form | United States |
List updated on July 22, 2026.
The legal detail, with the basis and purpose of each processing activity, is in the Privacy Policy.
VENDOR ASSESSMENT
What we send to your team.
If your company runs a formal vendor assessment, we have been through one. The material below goes out by email, and requests are answered within 5 business days.
Ask at dpa@levver.ai and tell us which product or project is under review.
- ·A completed information security and privacy questionnaire, on your form or ours.
- ·The Data Processing Agreement (DPA) for your legal team to review.
- ·The impact assessment (DPIA) and, where applicable, the records of processing (ROPA) for the product under review.
- ·The continuity plan and the incident response runbook.
- ·A non disclosure agreement, which we sign before any technical detail.
- ·A description of the architecture of whatever is contracted, at the depth your team asks for.
VULNERABILITY
Found a flaw? Tell us.
Write to dpa@levver.ai with what you saw and how to reproduce it. We confirm receipt within 2 business days and keep you posted until the case is closed.
Good faith research, without degrading the service and without touching anyone else's data, will not become a legal problem on our side. We would rather know.
The standard security contact file lives at levver.ai/.well-known/security.txt.
QUESTIONS
What buyers always ask.
Do you have ISO 27001 or SOC 2?+
Not today. Levver is a young company, and certification consumes time and money that currently go into what the client hired. What we do have is the base a certification sits on: an approved and reviewed policy set, information classification, impact assessment, records of processing, backup and incident runbooks, and an automated gate that blocks unsafe code. All of it is open to your audit. When volume justifies it, certification follows.
Where does my data live?+
It depends on the project, and it is written into the DPA. The site runs in São Paulo. In the products, the processing region is declared in the DPA, and today part of the infrastructure runs outside Brazil, including the AI model providers. In those cases the LGPD article 33 safeguard applies, with equivalent contractual clauses and, where applicable, the standard clauses published by the Brazilian authority. If your company requires residency in Brazil, that is assessed and set in the contract.
Does my data train your model?+
No. Neither ours nor the provider's. It is a clause in your contract and in the contract we hold with the provider. Content sent to the API is discarded after inference.
Who at Levver can access my data?+
Only whoever needs it for their role, with mandatory MFA on admin access. Access to sensitive data is logged, and the log is made available under contractual agreement.
What if I want to leave?+
The data is yours and it goes back to you. The DPA provides for return or deletion at the end of the contract. On custom projects, the code has been in your repository since day one, so there is no locked exit.
Will you sign our NDA and our DPA?+
We sign the NDA before any technical detail. On the DPA, we work with our template or review yours, whichever is faster for your legal team.
Have you been through a formal vendor assessment?+
Yes. We completed a full information security and privacy questionnaire in a formal procurement process, with an annex covering the impact assessment and the continuity plan. It is the same material that goes to your team.
NEXT STEP
Still have a question?
Bring your security team into the conversation. We answer questionnaires, sign NDAs, and walk through the architecture at whatever depth is needed.
