Skip to main content
Level Access logo

Level Access

Regulatory evidence

From testing and fixing to reporting, our digital accessibility platform provides everything you need for globally compliant

levelaccess.comCompliance and GRCLast verified 21 Sep 2026

Level Access against third-party requirements

For each regulation, how many of the requirements it places on your vendors Level Access’s public evidence reaches. Open one for every item with its date and source.

Documents on the trust centre

What the vendor lists, typed; public items can be read now, the rest are available on request.

14 documents listed on Level Access’s trust centre

trust.levelaccess.com
  • Architecture or data-flow diagram
    • UserWay-Architecture High Level_PDFUAon request · seen 21 Sep 2026
  • SOC 2 bridge letter
    • SOC 2 Type II Bridge Letteron request · seen 21 Sep 2026
  • Business continuity and disaster recovery plan
    • Level Access Business Continuity Statementon request · seen 21 Sep 2026
    • Level Access Business Continuity Test Recordon request · seen 21 Sep 2026
  • Incident response plan
    • Level Access Incident Response Plan v4.3on request · seen 21 Sep 2026
  • Cyber insurance certificate
    • Certificate of Insuranceon request · seen 21 Sep 2026
  • ISO certificate
    • Level Access ISO 27001 Certificateon request · seen 21 Sep 2026
  • ISO 27001 statement of applicability
    • Level Access SoAon request · seen 21 Sep 2026
  • Penetration test report
    • External Network Penetration Teston request · seen 21 Sep 2026
    • Web Application Penetration Test (Level Access Platform)on request · seen 21 Sep 2026
  • Security questionnaire (SIG, CAIQ, HECVAT)
    • HECVAT 4.10 (for Trust Center)on request · seen 21 Sep 2026
  • Security policy or overview
    • Level Access Information Security Policyon request · seen 21 Sep 2026
  • SOC 2 report
    • Level Access - 2025 - SOC 2 Type 2 Report - LAPon request · seen 21 Sep 2026
    • Level Access - 2025 - SOC 2 Type 2 Report - Widget Serviceson request · seen 21 Sep 2026

What the vendor says

Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.

  • Where data is hosted or processed

    Where does Level Access store data?

    We host customer data in AWS data centers located in the United States. The primary location is AWS US East-2 (Ohio), with backups in AWS US West-1 (Northern California). Widget Services data is stored in AWS Oregon.

    Regions named: USas of 21 Sep 2026Source

  • Where data is hosted or processed

    Where is data hosted?

    Level CI is hosted on Amazon Web Services (AWS) infrastructure. Customer data, accessibility findings, scan results, reporting information, and associated platform services are managed within AWS-hosted environments.

    as of 21 Sep 2026Source

  • International data transfers

    In case of data transfers outside the EU, which safeguards are implemented?

    We implement Standard Contractual Clauses (SCCs) for data transfers outside the EU. All personnel accessing data are subject to the same security and privacy controls, including contractual confidentiality, role-based access (RBAC), least privilege, multi-factor authentication (MFA), audit logging, and encryption in transit (TLS 1.2+) and at rest (AES-256).

    Regions named: EUas of 21 Sep 2026Source

  • Encryption

    How does Level Access encrypt data at-rest?

    Encryption at-rest must use AES-256, as per our Encryption standard, which is part of our Operational Security Policy (ISO 27001 certified, SOC 2 Type II audited).

    as of 21 Sep 2026Source

  • Encryption

    How is portable media encrypted?

    Portable storage devices are encrypted using AES-256.

    as of 21 Sep 2026Source

  • Encryption

    How does Level Access encrypt data in-transit?

    All data must be transported over TLS 1.2 or higher, as per our Encryption standard, which is part of our Operational Security Policy (ISO 27001 certified, SOC 2 Type II audited).

    as of 21 Sep 2026Source

  • Encryption

    How are encryption keys managed and accessed?

    Encryption keys are managed through AWS KMS with automated rotation. Access is restricted to authorized personnel and follows structured key compromise mitigation procedures.

    as of 21 Sep 2026Source

  • Use of customer data to train models

    Does Level CI use customer code or data to train AI models?

    Level CI does not use customer code or data to train any AI models. All AI features operate using pre-trained third-party models and are governed by our AI policy, which prohibits the use of customer data for model training or fine-tuning.

    as of 21 Sep 2026Source

  • Use of customer data to train models

    Does the Widget use customer data to train AI models?

    No. Models are pre-trained and never fine-tuned on customer or end-user data.

    as of 21 Sep 2026Source

  • Penetration testing

    How often is penetration testing conducted?

    Third-party penetration testing is conducted annually.

    as of 21 Sep 2026Source

  • Data retention and deletion

    What is the retention period for stored data?

    Data retention in Level CI varies based on the type of data being stored. Organization and user account information may be retained indefinitely to support ongoing customer access and platform operations. Certain operational data, including Delta ALM instances and closed issues, are retained for 30 days before removal.

    as of 21 Sep 2026Source

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.