#open for more workLearn more

Security

Built for the most confidential data there is.

Encryption in every layer, EU hosting with Hetzner in Germany and an audit trail with tamper detection. Here is what we have built, and what we do not yet have on paper.

Security statusLive

EU hosting

Germany and Sweden

Encryption

AES-256 · TLS 1.3

Audit trail

HMAC-signed

2FA

Mandatory

Operations in Nuremberg. Documents and backups in Stockholm.EU

Defence in depth

Security in every layer.

From the connection down to the individual cell in the database. Every layer is built so no one sees more than they should, and nothing is lost.

Encrypted in transit.
Encrypted at rest.

Every connection runs on TLS 1.3, and all data sits encrypted with AES-256. The most sensitive fields get one more layer.

  • TLS 1.3 for all connections
  • AES-256 for all data at rest
  • Field-level encryption for national ID and payment data
  • HMAC-signed audit logs with tamper-detection

No one sees more than
they should.

Access follows the role: partner, lawyer, associate, secretary, bookkeeper, client. And every action leaves a trace.

  • Role-based access control (RBAC)
  • Mandatory 2FA: TOTP, SMS, national eID when enabled
  • Microsoft SSO with existing Entra ID groups
  • Ethical walls between teams and an audit trail on everything

Daily backup.
Two years back.

The database is backed up automatically every night and stored encrypted separately from production. The ladder thins out the further back you go, and it reaches two years.

  • Daily automatic backup of the database
  • The ladder: 7 days, 16 days, 8 weeks, 4 months, 2 years
  • Backups sit encrypted in Amazon S3 in Stockholm
  • Document files live in object storage, not in the database backup

Standards and status

We also write down what we don't have.

See our status on standards

EU hosting

Germany and Sweden

GDPR

EU data protection

AES-256 · TLS 1.3

Encryption in every layer

Audit trail

HMAC-signed

Data residency

EU hosting. Germany and Sweden.

Levano runs on Hetzner in Germany, with the database physically in Nuremberg. Documents and backups sit in Amazon S3 in Stockholm. Your cases and documents stay in the EU. The few vendors that process data outside the EU are named on our sub-processor list.

Application and database
Nuremberg, Germany
Documents and backups
Stockholm, Sweden
Transfer outside the EU
Only via listed sub-processors
Clients · Denmark
Primary · Nuremberg
Documents and backups · Stockholm
Hetzner · Germany and AWS · Sweden0 transfers out of the EU

AI security

The AI doesn't train on your data.

Levano uses Anthropic Claude as its AI vendor. It's the first question lawyers ask about AI, so here's the short answer: your data is used to answer you, and it never becomes training data.

  • Prompts are used only to answer your question
  • Anthropic never trains on your input
  • We send only the context the task requires, not the entire case
  • Citations provide sources so you can verify the answer
  • A data processing agreement with Anthropic for Claude

If the law changes (e.g. the EU AI Act), we update the setup.

Anthropic Claude · data processing agreementActive
  1. 1

    Your prompt

    Only the context the task requires

  2. 2

    Claude responds

    Used only to answer you

  3. 3

    No training

    Your data never becomes training data

Compliance

We support your firm's work.

Levano is built for Danish lawyers, so the rules are part of the foundation. The duty to comply stays with the firm, which is why we write down what the system does and what it does not.

The Danish Bar and Law Society

Built for the bar association's quality framework. The audit trail can be pulled for a quality inspection.

GDPR

A data processing agreement written for law firms, an impact assessment, retention rules and deletion.

AML legislation

Risk assessment, PEP checks and monitoring support the firm's customer due diligence. Reporting is and remains the firm's own.

Client account rules

Separated account management. Reconciliation proposes a match that a lawyer approves.

Public sector customers

We answer security questionnaires and tender requirements with the documentation we hold.

Trust Center

Get all the documentation.

The data processing agreement, the sub-processor list, a description of the security measures and our incident response process. Request the pack and we send what we have, and write down what we don't.

We answer requests within 2 business days.

Ask our team

Questions about security?

Security questions are handled directly by our tech team. CTO Victor Brøgger is responsible. Write to us and you'll hear from a person, not a form.

contact@levano.io

Victor Brøgger · CTO, Levano

FAQ

Questions about security.

  • The application and database run with Hetzner in Germany, the database physically in Nuremberg. Documents and backups sit in Amazon S3 in Stockholm. No customer data leaves the EU.

Pilot access opens Q4 2026 · limited spots

Ready to leave on time?

Levano opens to new pilot firms in Q4 2026. Join the waitlist now and be among the first to get access.

Secure your spot

Join the waitlist. We will send an invitation when pilot access opens.

We never share your email. Unsubscribe anytime.

  • No commitment
  • Takes 2 minutes
  • Reply within 24 hours