The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
From testing and fixing to reporting, our digital accessibility platform provides everything you need for globally compliant
For each regulation, how many of the requirements it places on your vendors Level Access’s public evidence reaches. Open one for every item with its date and source.
What the vendor lists, typed; public items can be read now, the rest are available on request.
14 documents listed on Level Access’s trust centre
trust.levelaccess.comAnswers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where does Level Access store data?
“We host customer data in AWS data centers located in the United States. The primary location is AWS US East-2 (Ohio), with backups in AWS US West-1 (Northern California). Widget Services data is stored in AWS Oregon.”
Regions named: USas of 21 Sep 2026Source
Where data is hosted or processed
Where is data hosted?
“Level CI is hosted on Amazon Web Services (AWS) infrastructure. Customer data, accessibility findings, scan results, reporting information, and associated platform services are managed within AWS-hosted environments.”
as of 21 Sep 2026Source
International data transfers
In case of data transfers outside the EU, which safeguards are implemented?
“We implement Standard Contractual Clauses (SCCs) for data transfers outside the EU. All personnel accessing data are subject to the same security and privacy controls, including contractual confidentiality, role-based access (RBAC), least privilege, multi-factor authentication (MFA), audit logging, and encryption in transit (TLS 1.2+) and at rest (AES-256).”
Regions named: EUas of 21 Sep 2026Source
Encryption
How does Level Access encrypt data at-rest?
“Encryption at-rest must use AES-256, as per our Encryption standard, which is part of our Operational Security Policy (ISO 27001 certified, SOC 2 Type II audited).”
as of 21 Sep 2026Source
Encryption
How is portable media encrypted?
“Portable storage devices are encrypted using AES-256.”
as of 21 Sep 2026Source
Encryption
How does Level Access encrypt data in-transit?
“All data must be transported over TLS 1.2 or higher, as per our Encryption standard, which is part of our Operational Security Policy (ISO 27001 certified, SOC 2 Type II audited).”
as of 21 Sep 2026Source
Encryption
How are encryption keys managed and accessed?
“Encryption keys are managed through AWS KMS with automated rotation. Access is restricted to authorized personnel and follows structured key compromise mitigation procedures.”
as of 21 Sep 2026Source
Use of customer data to train models
Does Level CI use customer code or data to train AI models?
“Level CI does not use customer code or data to train any AI models. All AI features operate using pre-trained third-party models and are governed by our AI policy, which prohibits the use of customer data for model training or fine-tuning.”
as of 21 Sep 2026Source
Use of customer data to train models
Does the Widget use customer data to train AI models?
“No. Models are pre-trained and never fine-tuned on customer or end-user data.”
as of 21 Sep 2026Source
Penetration testing
How often is penetration testing conducted?
“Third-party penetration testing is conducted annually.”
as of 21 Sep 2026Source
Data retention and deletion
What is the retention period for stored data?
“Data retention in Level CI varies based on the type of data being stored. Organization and user account information may be retained indefinitely to support ongoing customer access and platform operations. Certain operational data, including Delta ALM instances and closed issues, are retained for 30 days before removal.”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.