Level is a powerful remote monitoring and management platform. This Policy protects customers, end users, third parties, and the Services from unauthorized or harmful use. It forms part of the Terms of Service.
Customer is responsible for its users, credentials, integrations, scripts, automations, and other activity through its account. A customer may manage only systems and data it owns, controls, or is authorized to manage.
1. Unauthorized Access and Harm
Customer must not use Level to:
- Access or attempt to access a device, account, network, tenant, service, or data without authorization, beyond authorization, or after authorization is revoked.
- Obtain credentials, elevate privileges, move laterally, establish persistence, evade security controls, or operate command-and-control infrastructure without authorization.
- Destroy, encrypt, corrupt, alter, exfiltrate, or make data unavailable without authorization.
- Introduce malware, ransomware, spyware, credential theft, a backdoor, a cryptominer, or other malicious code.
- Interfere with, overload, or degrade Level, an Endpoint, a network, or another service.
- Conceal the origin, identity, purpose, or destination of prohibited activity.
Authorized administration, incident response, penetration testing, vulnerability validation, and forensic work are permitted within the customer’s documented authority.
2. Surveillance, Privacy, and People
Customer must not use Level for unlawful or abusive surveillance, stalking, harassment, coercion, discrimination, retaliation, exploitation, or control. Customer must not collect passwords, private messages, screen content, keystrokes, files, precise location, or other sensitive information without appropriate authority, notice, and lawful purpose.
Legitimate IT support, security monitoring, compliance, and device administration are permitted when Customer uses proportionate access, roles, notices, and safeguards. Customer is responsible for workplace, communications, interception, privacy, employment, and recording laws that apply to its use.
Customer must not use the Services to exploit a child or vulnerable person, distribute child sexual abuse material or non-consensual intimate imagery, facilitate trafficking or credible violence, or target a person based on protected status for harm. Report an immediate danger to local emergency services before contacting Level.
3. Fraud and Deceptive Activity
Customer must not use Level for phishing, impersonation, account takeover, payment fraud, deceptive technical support, unauthorized software deployment, theft, extortion, spam, or evasion of a platform or provider’s security rules. Customer must not create accounts or rotate identities, payment methods, domains, IP addresses, or infrastructure to evade a Level restriction.
4. Credentials, Access, and Resale
Customer must protect credentials, use individual accounts where provided, scope service accounts and API tokens, remove access that is no longer needed, and notify Level of suspected compromise.
Customer may not share a personal login, sell account access, rent the Services, or operate them as an unauthorized remote-access service. An MSP may use Level for its clients under the Terms but remains responsible for client authorization and activity.
5. Automation, APIs, and AI
Customer must supervise scripts, monitors, automations, APIs, CLI tools, integrations, and AI systems. Customer must test material actions, limit targets and permissions, use reasonable rate limits and budgets, monitor results, and maintain an effective stop mechanism.
Automation or AI may not be used to bypass approval or safety controls, generate or deploy harmful code, conduct prohibited surveillance, make a high-impact decision about a person without required human review, or shift responsibility away from Customer. Actions authenticated with Customer credentials are Customer Actions.
6. High-Risk and Regulated Use
The Services are not designed for systems where failure could reasonably cause death, personal injury, or catastrophic physical or environmental damage. Customer may not use Level in weapons, emergency control, life support, autonomous vehicles, critical safety systems, or similar environments unless a signed Order expressly authorizes the use.
Customer must comply with export controls and sanctions. Customer may not use the Services for prohibited parties, territories, or transactions, except as authorized by law.
Customer must not submit protected health information unless Level authorizes the use in writing and the parties sign any required Business Associate Agreement. Separate Business Associate Agreements and Data Processing Addenda for internal IT and MSP use are available through support@level.io.
7. Resource Library
A person submitting a script, monitor, automation, template, or other Resource must own or have rights to it, accurately describe its purpose and risks, disclose elevated permissions or destructive behavior, identify applicable licenses, and remove secrets, tracking, malicious code, and unnecessary Personal Information.
Level may test, format, quarantine, reject, remove, or report a Resource. Publication or a “verified” label is not a warranty that it is secure, compatible, or fit for a customer’s environment.
8. Security Research
Good-faith research into Level systems is governed by the Vulnerability Disclosure Policy. Research that follows that policy is authorized and receives the safe harbor described there. A researcher does not need separate written permission before conducting in-scope testing under that policy.
Report a suspected vulnerability to security@level.io.
9. Enforcement and Appeal
Level may use automated rules, risk scoring, cross-account signals, abuse reports, and staff review to identify compromise or suspected violations. A signal can have an innocent explanation, so Level ordinarily considers context and corroborating information before a material account-level decision. Immediate risk may require action first and review afterward.
Depending on severity, Level may warn Customer, request information, increase monitoring, restrict an action or credential, quarantine an integration or Endpoint, suspend or terminate an account, preserve evidence, or report conduct when required or permitted by law. When practical, Level will limit the action to the affected scope and provide a general explanation.
Customer may appeal a material suspension or termination through support@level.io. Level will provide human review and may restore access when it determines the risk has been resolved or the action was mistaken. Level may require identity, authority, account-security, or corrective-action verification.
10. Reporting and Changes
Report suspected abuse to support@level.io. Include the affected account, device, time, evidence, and immediate safety concern when available. Do not send secrets or unnecessary Personal Information in ordinary email.
Level may update this Policy for changes in law, risk, or the Services. Material changes receive notice as described in the Terms.