Standards and status
We don't have it in writing yet.
A certification is documentation, not marketing, and we don't have one yet. Here is which standards we build to, what we can show today, and what is missing.
EU hosting
Germany and Sweden
Encryption
AES-256 · TLS 1.3
Audit trail
HMAC-signed
2FA
Mandatory
Standards
What we meet.
We mark the status of each standard. None of them is confirmed by an independent auditor today, and there is no ISAE 3000 report or equivalent auditor's statement on the controls described. Everything below is verified by us, and the sources can be shown.
ISO/IEC 27001:2022
Not certifiedThe international standard for managing information security.
What it covers
- Access control
- Cryptography
- Physical security
- Supplier management
- Incident management
- Business continuity
How we do it
We build to the standard's controls: access management, encryption, supplier management and logging. We have not completed an accredited audit, so we hold no certificate.
The description of the measures can be requested via the Trust Center.
ISO/IEC 42001
Not certifiedThe world's first international standard for AI Management Systems, published in 2023.
What it covers
- AI risk assessment
- Model governance
- Data quality for AI
- Transparency
- Accountability
How we do it
A specific AI policy and a data processing agreement with Anthropic for Claude. Your data never becomes training data, and every answer carries its sources.
We work to the standard. We are not certified in it.
GDPR
Ongoing workThe EU's data protection regulation. It isn't a certification but a duty, and we have run an impact assessment so we can show where we stand.
What it covers
- Data storage
- Consent
- Retention
- Atomic deletion
- Client requests
How we do it
Data stays in the EU: operations in Germany, documents and backups in Sweden. The impact assessment also names the weaknesses we know of, not only the controls we have.
A data processing agreement written for law firms. The draft is in legal review.
SOC 2 Type II
PlannedAn AICPA audit framework. Type II assesses operational effectiveness over an audited operating period.
What it covers
- Security
- Availability
- Processing Integrity
- Confidentiality
- Privacy
How we do it
Not started yet. A Type II report requires an audited operating period, and it sits on our roadmap below.
There is no SOC 2 report for Levano today.
The Danish Bar and Law Society
SupportedThe quality framework and guidelines for electronic case handling.
What it covers
- Quality framework
- AML rules
- Client account rules
- Conflict checks
- Ethical walls
How we do it
Functionality built specifically for Danish lawyers. The audit trail can be pulled for a quality inspection. The bar association does not approve IT systems, so responsibility for the quality framework stays with the firm.
Functional specification available on request.
Industry standards
We also follow
Beyond the standards above, we work to the recognised security frameworks.
OWASP Top 10
The ten most critical web security risks, addressed in code and review.
CIS Controls
Prioritised controls for information security.
NIST Cybersecurity Framework
A framework to identify, protect, detect and respond.
Roadmap
The next milestones.
2026
Penetration testing programme
Annual tests by external security specialists.
2027
SOC 2 Type II
Operational audit across a 6 to 12 month period.
2027+
ISO 27017 + 27018
Cloud security and protection of PII in the cloud.
Need it for a tender?
Talk to our tech team.
Need the documentation for a tender or vendor review? Request it via the Trust Center, or write to the team directly. You get what we have, and a line about what we don't.
Victor Brøgger · CTO, Levano
