Security
Built for the most confidential data there is.
Encryption in every layer, EU hosting with Hetzner in Germany and an audit trail with tamper detection. Here is what we have built, and what we do not yet have on paper.
EU hosting
Germany and Sweden
Encryption
AES-256 · TLS 1.3
Audit trail
HMAC-signed
2FA
Mandatory
Defence in depth
Security in every layer.
From the connection down to the individual cell in the database. Every layer is built so no one sees more than they should, and nothing is lost.
Encrypted in transit.
Encrypted at rest.
Every connection runs on TLS 1.3, and all data sits encrypted with AES-256. The most sensitive fields get one more layer.
- TLS 1.3 for all connections
- AES-256 for all data at rest
- Field-level encryption for national ID and payment data
- HMAC-signed audit logs with tamper-detection
No one sees more than
they should.
Access follows the role: partner, lawyer, associate, secretary, bookkeeper, client. And every action leaves a trace.
- Role-based access control (RBAC)
- Mandatory 2FA: TOTP, SMS, national eID when enabled
- Microsoft SSO with existing Entra ID groups
- Ethical walls between teams and an audit trail on everything
Daily backup.
Two years back.
The database is backed up automatically every night and stored encrypted separately from production. The ladder thins out the further back you go, and it reaches two years.
- Daily automatic backup of the database
- The ladder: 7 days, 16 days, 8 weeks, 4 months, 2 years
- Backups sit encrypted in Amazon S3 in Stockholm
- Document files live in object storage, not in the database backup
Standards and status
We also write down what we don't have.
EU hosting
Germany and Sweden
GDPR
EU data protection
AES-256 · TLS 1.3
Encryption in every layer
Audit trail
HMAC-signed
Data residency
EU hosting. Germany and Sweden.
Levano runs on Hetzner in Germany, with the database physically in Nuremberg. Documents and backups sit in Amazon S3 in Stockholm. Your cases and documents stay in the EU. The few vendors that process data outside the EU are named on our sub-processor list.
- Application and database
- Nuremberg, Germany
- Documents and backups
- Stockholm, Sweden
- Transfer outside the EU
- Only via listed sub-processors
AI security
The AI doesn't train on your data.
Levano uses Anthropic Claude as its AI vendor. It's the first question lawyers ask about AI, so here's the short answer: your data is used to answer you, and it never becomes training data.
- Prompts are used only to answer your question
- Anthropic never trains on your input
- We send only the context the task requires, not the entire case
- Citations provide sources so you can verify the answer
- A data processing agreement with Anthropic for Claude
If the law changes (e.g. the EU AI Act), we update the setup.
- 1
Your prompt
Only the context the task requires
- 2
Claude responds
Used only to answer you
- 3
No training
Your data never becomes training data
Compliance
We support your firm's work.
Levano is built for Danish lawyers, so the rules are part of the foundation. The duty to comply stays with the firm, which is why we write down what the system does and what it does not.
The Danish Bar and Law Society
Built for the bar association's quality framework. The audit trail can be pulled for a quality inspection.
GDPR
A data processing agreement written for law firms, an impact assessment, retention rules and deletion.
AML legislation
Risk assessment, PEP checks and monitoring support the firm's customer due diligence. Reporting is and remains the firm's own.
Client account rules
Separated account management. Reconciliation proposes a match that a lawyer approves.
Public sector customers
We answer security questionnaires and tender requirements with the documentation we hold.
Trust Center
Get all the documentation.
The data processing agreement, the sub-processor list, a description of the security measures and our incident response process. Request the pack and we send what we have, and write down what we don't.
Ask our team
Questions about security?
Security questions are handled directly by our tech team. CTO Victor Brøgger is responsible. Write to us and you'll hear from a person, not a form.
Victor Brøgger · CTO, Levano
FAQ
Questions about security.
Ready to leave on time?
Levano opens to new pilot firms in Q4 2026. Join the waitlist now and be among the first to get access.
Secure your spot
Join the waitlist. We will send an invitation when pilot access opens.
- No commitment
- Takes 2 minutes
- Reply within 24 hours
