#open for more workLearn more

Standards and status

We don't have it in writing yet.

A certification is documentation, not marketing, and we don't have one yet. Here is which standards we build to, what we can show today, and what is missing.

Security statusLive

EU hosting

Germany and Sweden

Encryption

AES-256 · TLS 1.3

Audit trail

HMAC-signed

2FA

Mandatory

Operations in Nuremberg. Documents and backups in Stockholm.EU

Standards

What we meet.

We mark the status of each standard. None of them is confirmed by an independent auditor today, and there is no ISAE 3000 report or equivalent auditor's statement on the controls described. Everything below is verified by us, and the sources can be shown.

ISO/IEC 27001:2022

Not certified

The international standard for managing information security.

What it covers

  • Access control
  • Cryptography
  • Physical security
  • Supplier management
  • Incident management
  • Business continuity

How we do it

We build to the standard's controls: access management, encryption, supplier management and logging. We have not completed an accredited audit, so we hold no certificate.

The description of the measures can be requested via the Trust Center.

ISO/IEC 42001

Not certified

The world's first international standard for AI Management Systems, published in 2023.

What it covers

  • AI risk assessment
  • Model governance
  • Data quality for AI
  • Transparency
  • Accountability

How we do it

A specific AI policy and a data processing agreement with Anthropic for Claude. Your data never becomes training data, and every answer carries its sources.

We work to the standard. We are not certified in it.

GDPR

Ongoing work

The EU's data protection regulation. It isn't a certification but a duty, and we have run an impact assessment so we can show where we stand.

What it covers

  • Data storage
  • Consent
  • Retention
  • Atomic deletion
  • Client requests

How we do it

Data stays in the EU: operations in Germany, documents and backups in Sweden. The impact assessment also names the weaknesses we know of, not only the controls we have.

A data processing agreement written for law firms. The draft is in legal review.

SOC 2 Type II

Planned

An AICPA audit framework. Type II assesses operational effectiveness over an audited operating period.

What it covers

  • Security
  • Availability
  • Processing Integrity
  • Confidentiality
  • Privacy

How we do it

Not started yet. A Type II report requires an audited operating period, and it sits on our roadmap below.

There is no SOC 2 report for Levano today.

The Danish Bar and Law Society

Supported

The quality framework and guidelines for electronic case handling.

What it covers

  • Quality framework
  • AML rules
  • Client account rules
  • Conflict checks
  • Ethical walls

How we do it

Functionality built specifically for Danish lawyers. The audit trail can be pulled for a quality inspection. The bar association does not approve IT systems, so responsibility for the quality framework stays with the firm.

Functional specification available on request.

Industry standards

We also follow

Beyond the standards above, we work to the recognised security frameworks.

OWASP Top 10

The ten most critical web security risks, addressed in code and review.

CIS Controls

Prioritised controls for information security.

NIST Cybersecurity Framework

A framework to identify, protect, detect and respond.

Roadmap

The next milestones.

  1. 2026

    Penetration testing programme

    Annual tests by external security specialists.

  2. 2027

    SOC 2 Type II

    Operational audit across a 6 to 12 month period.

  3. 2027+

    ISO 27017 + 27018

    Cloud security and protection of PII in the cloud.

Need it for a tender?

Talk to our tech team.

Need the documentation for a tender or vendor review? Request it via the Trust Center, or write to the team directly. You get what we have, and a line about what we don't.

contact@levano.io

Victor Brøgger · CTO, Levano