Compliance
Security standards you can verify.
Level maintains formal compliance controls and undergoes regular independent security testing.
Compliance and certifications.
The details your security review needs.
SOC 2 Type II
Independently audited security, availability, and confidentiality controls. Request the report under NDA at support@level.io.
ISO
ISO certification is in progress. Email our team at support@level.io for the current status and documentation available for your review.
HIPAA
Support for covered entities and business associates. A Business Associate Agreement is available on request via support@level.io (separate versions for internal IT and MSPs).
GDPR
GDPR-aligned processing of personal data belonging to residents of the European Union. A Data Processing Addendum is available on request via support@level.io (separate versions for internal IT and MSPs).

Audited
SOC 2 Type II
What SOC 2 Type II is
A SOC 2 Type II examination evaluates how controls operate over time against the AICPA Trust Services Criteria.
What it means for you
You can review independently examined controls for security, availability, and confidentiality instead of relying on Level's claims alone.
Where Level stands
Level maintains a SOC 2 Type II report that is available for security reviews under NDA.
What to do today
Email support@level.io to request the report under NDA. Include your organization name and contact details.

In Progress
ISO
What ISO is
ISO certification is an independent assessment of whether an organization meets the requirements of a defined international standard.
What it means for you
Once complete, the certification will give you an independent reference point for evaluating Level's policies and controls.
Where Level stands
Level's ISO certification is in progress. Current documentation is available for your review on request.
What to do today
Email support@level.io for the current status and documentation available for your review while the certification process continues.

BAA Available
HIPAA
What HIPAA addresses
HIPAA establishes requirements for protecting health information handled by covered entities and business associates.
What it means for you
You can evaluate Level for use in a HIPAA-regulated environment and request a BAA when your organization needs one.
Where Level stands
Level offers separate Business Associate Agreements for internal IT teams and MSPs.
What to do today
Email support@level.io to request the BAA that matches your organization. Separate versions are available for internal IT teams and MSPs.

DPA Available
GDPR
What GDPR addresses
GDPR establishes data protection requirements for personal data belonging to residents of the European Union.
What it means for you
You can evaluate how Level handles personal data belonging to EU residents and request a DPA that matches your organization.
Where Level stands
Level's data processing is aligned with GDPR requirements, and separate DPAs are available for internal IT teams and MSPs.
What to do today
Email support@level.io to request the DPA that matches your organization.
Security review details.
How do I get Level's SOC 2 report?
Contact support@level.io with your organization name and contact details. Reports are shared under NDA.
Does Level sign Business Associate Agreements?
Yes. A Business Associate Agreement is available on request via support@level.io (separate versions for internal IT and MSPs).
Does Level offer a Data Processing Addendum?
Yes. A Data Processing Addendum is available on request via support@level.io (separate versions for internal IT and MSPs).
How often does Level perform penetration testing?
Quarterly. Independent vendors test the web application, API, and agent endpoints.
Where can I ask about ISO or another security standard?
ISO certification is in progress. Use the contact form or email support@level.io for current status and available documentation.
Need documentation for your review?
Tell us what your team needs and we’ll route the request.