Security

Prove your security posture, not just claim it.

Control access, encrypt data, and keep the evidence a review needs. SOC 2 Type II.

A visual of Level security controls.

Turn endpoint signals into a security posture.

Know which gaps to close first.

  • OS patchingScanning
  • AntivirusScanning
  • FirewallScanning
  • Disk encryptionScanning

Set the boundary once.

Roles, device scope, and network rules keep it enforced.

  • Grant only the permissions each user needs.

    Custom roles and write protections control which accounts, devices, and settings each user can view or change.

  • Scope technicians to the right devices.

    Group-level access keeps each technician inside the clients, sites, or fleets they are responsible for.

  • Allow known networks. Deny the rest.

    IP allow and deny lists restrict access from networks that do not meet your security policy.

  • Set password policy for every user.

    Require complex passwords and enforce account standards alongside two-factor authentication.

Control who gets in, on your terms.

Every login method Level supports, enforced everywhere.

single sign-on through Okta, Google, or Authentik

Sign on through your identity provider.

Connect Okta, Google, or Authentik so access follows the login policy your team already manages.

second-factor authentication required for every user

Two-factor is available.

Add a second factor on any account, including admins and technicians.

end-to-end encrypted technician and endpoint traffic

Remote sessions stay encrypted from start to finish.

Session traffic uses a P2P connection when network conditions allow, and an end-to-end encrypted Level relay when they do not. Encrypted either way.

activity log showing identities, actions, and timestamps

Every action lands in the log.

Activity logging records who signed in, what ran, and when, across your whole fleet.

Protect data across the path.

Restrict infrastructure access and keep recovery within reach.

  • Encrypt traffic in transit.

    HTTPS and encrypted remote sessions protect data between browsers, services, and managed endpoints.

  • Keep production access narrow.

    Identity and secrets controls restrict who can reach production systems and customer data.

  • Put private systems behind network controls.

    Private addressing, firewalls, and traffic monitoring reduce exposed paths into Level infrastructure.

  • Encrypt data at rest.

    Customer data remains encrypted in production databases, server storage, and backups.

  • Review every outside provider.

    Level evaluates the vendors that process customer data and requires strong account security for staff.

  • Record the actions that matter.

    Sign-ins, sessions, script runs, and configuration changes stay available for investigation and review.

Respond before an issue becomes an outage.

Detect it early. Recover cleanly and explain what changed.

  • Know when something changes.

    System metrics, traffic, and application logs feed alerts to engineers, with escalation when risk rises.

  • Recover with a known path.

    Versioned releases, backups, and rollback procedures keep recovery work deliberate when an incident occurs.

  • Close the loop.

    Status updates keep customers informed, and post-incident reviews turn each event into stronger controls.

Give every security review a clearer starting point.

Audited controls, available agreements, and certifications in progress make Level's current posture easy to understand.

Audited

SOC 2 Type II

In Progress

ISO

BAA Available

HIPAA

DPA Available

GDPR

Make every change earn its way to production.

Small releases, review, testing, and rollback keep risk contained.

  • Review the security boundary first.

    Changes start with the authentication, authorization, and data access they can affect.

  • Keep releases small.

    Frequent, focused changes are easier to understand, test, review, and reverse.

  • Review every change.

    Code moves forward only after another engineer has examined the implementation and its risk.

  • Test before deployment.

    Automated checks and release validation catch regressions before they reach customer environments.

  • Keep rollbacks ready.

    Version control and repeatable delivery make prior application versions available when needed.

  • Train for secure delivery.

    Internal policies and developer training keep security part of day-to-day product decisions.

Not even the people who built Level have standing access to your devices.

That boundary exists by design.

  • Endpoint actions start with your account.

    Remote control, background management, shells, scripts, and files must begin from an authorized Level account—not from standing staff access.

  • Support access starts with your approval.

    You explicitly grant temporary support access. Level personnel may act only through the authorized customer account, within the scope and duration you approve. Access expires automatically.

  • Agent privilege stays on the device.

    The Level agent may run as SYSTEM or root to do the work you request. That privilege does not give Level personnel standing access to your devices.

  • Infrastructure access stops at Level's data.

    Server, database, log, and device-metadata access cannot be used to open endpoint sessions, shells, scripts, files, or controls.

  • Sessions stay encrypted, peer-to-peer when possible.

    Sessions use P2P when possible or an end-to-end encrypted Level relay. These sessions do not create persistent access for Level personnel. Level does not record remote-control sessions.

  • A new access mechanism would be a material change.

    Standing staff access would require changes to the agent and security architecture. Level will provide reasonable notice if it introduces standing administrative access for Level personnel.

Straight answers on how Level protects your fleet.

The questions security reviewers actually ask.

Can I get a copy of Level's SOC 2 report?

Yes. Level maintains a SOC 2 Type II report. Request it during your security review and we'll share it under NDA. Current compliance details are also available on our compliance page.

Does Level sign a Business Associate Agreement?

Yes. Email support@level.io to request a BAA. There are separate versions for internal IT and MSPs.

What is Level's ISO certification status?

ISO certification is in progress. Email support@level.io for current status and documentation. Current compliance details are also on our compliance page.

Is Level an antivirus or endpoint protection suite?

No. Level shows antivirus, firewall, patch, and disk encryption status as posture signals. It does not replace the endpoint protection tools behind those signals.

Are remote sessions encrypted?

Yes. Session traffic uses a P2P connection when network conditions allow, and an end-to-end encrypted Level relay when they do not. The session stays encrypted from the moment it opens until the technician disconnects.

Can Level employees remotely access my devices?

No. Level employees do not have standing remote or administrative access to managed endpoints. Access to Level's servers, databases, or infrastructure does not provide the ability to remotely control an endpoint. A customer must explicitly grant temporary support access before Level personnel can access the customer's Level account and interact with devices through it.

Does Level support single sign-on?

Yes. Level supports SSO through Okta, Google, and Authentik, so access follows your existing identity provider.

Is activity logged?

Every session, script run, and configuration change is recorded in the activity log, so you can see who did what and when.

Can we restrict access by role, device group, or network?

Yes. Role-based permissions and write protections control what each user can view or change, device groups scope the endpoints they can reach, and IP allow and deny lists restrict access by network.

How does Level protect customer data and infrastructure?

Level encrypts customer data in transit and at rest, limits production access, and places private infrastructure behind firewalls and traffic monitoring. External providers are reviewed before they handle customer data.

How does Level detect and respond to platform abuse?

Level combines account, authentication, billing, device, network, script, automation, command, and execution signals with cross-account correlations, abuse reports, automated analysis, and staff review. We look for compromised-account activity and patterns consistent with unauthorized remote-access-tool delivery or other prohibited use under the Abuse and Restricted Use Policy. Credible risk may trigger closer monitoring, an account review, restricted activity, suspension, evidence preservation, or reporting when required or permitted by law. This monitoring uses information processed by the Level platform and does not give Level personnel standing access to customer endpoints.

What happens if Level has a security incident?

Monitoring and logs feed an escalation process, while versioned releases, backups, and rollback procedures support recovery. Level communicates material service events and reviews incidents afterward to strengthen the controls that failed.

How does Level develop and release software securely?

Level ships focused changes through code review, automated checks, release validation, and version-controlled deployment. Internal policies and training keep security part of the engineering process.

How do I report a vulnerability?

Email security@level.io with the affected surface, steps to reproduce, and any supporting evidence. Our team will route the report for investigation.

Does the free tier get the same security?

Yes. SOC 2 controls, two-factor authentication, encrypted sessions, and activity logging apply to every plan, including your first 10 free devices.

Start with a security posture you can prove.

First 10 devices free.