Introduction
Level maintains formal compliance certifications and undergoes regular third-party security testing. This article summarizes the current compliance posture and how to request documentation.
For questions or concerns not covered here, ask our support team.
How to request documentation
Ask our support team for the document you need and we will send it to you. Open the Messenger from the Level app and tell us which document you need, along with your organization name. If you are already in a conversation with us, just ask there, there is no separate form to fill out or address to write to.
ℹ️ NOTE: SOC 2 reports and penetration test reports are shared under NDA, so those requests go through a short review before we send them. Everything else, including a W-9, is sent to you directly with no NDA or approval step.
SOC 2
Level is SOC 2 compliant. The audit evaluates security, availability, and confidentiality controls against the AICPA Trust Services Criteria.
To request a copy of the SOC 2 report, ask our support team.
ℹ️ NOTE: SOC 2 reports are shared under NDA. Include your organization name and contact details in your request.
HIPAA
Level supports HIPAA compliance requirements for covered entities and business associates. A Business Associate Agreement (BAA) is available on request.
To initiate a BAA or discuss HIPAA-specific requirements, ask our support team.
GDPR
Level complies with the General Data Protection Regulation (GDPR) for the processing of personal data belonging to EU residents.
For data processing questions or to submit a data subject request, ask our support team.
Penetration Testing
External security vendors conduct penetration tests quarterly. Testing covers the web application, API, and agent endpoints.
To request a copy of the latest penetration test report, ask our support team.
ℹ️ NOTE: Penetration test reports are shared under NDA, similar to SOC 2 reports.
Tax Documentation (W-9)
Level keeps a completed, signed IRS Form W-9 on file. Ask our support team and we will reply with a copy attached. There is no NDA, review, or approval process for the W-9.
We can also complete vendor setup packets, bank verification letters, and W-9 requests submitted through a vendor portal.
More Information
For a broader overview of Level's security architecture, encryption practices, and infrastructure, visit level.io/features/security.
FAQ
How do I get a copy of the SOC 2 report? Ask our support team and include your organization name. Reports are shared under NDA.
Does Level sign BAAs for HIPAA? Yes. Ask our support team to start the BAA process.
Can I get a copy of Level's W-9? Yes. Ask our support team and we will send it to you with no NDA or approval step.
How often does Level do penetration testing? Quarterly, using external third-party vendors.
Who do I contact with a compliance question not covered here? Ask our support team. We handle compliance, security documentation, and data processing inquiries.
